Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1427

Опубликовано: 11 фев. 2015
Источник: redhat
CVSS3: 6.5
CVSS2: 6.8

Описание

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

It was reported that Elasticsearch versions 1.3.0-1.3.7 and 1.4.0-1.4.2 have vulnerabilities in the Groovy scripting engine. The vulnerability allows an attacker to construct Groovy scripts that escape the sandbox and execute shell commands as the user running the Elasticsearch Java VM.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1amq-6Not affected
Red Hat JBoss Enterprise Web Server 1fuse-6Not affected
Red Hat JBoss Enterprise Web Server 1fuse-amq-7Not affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7Not affected
Red Hat OpenShift Enterprise 2openshift-origin-cartridge-fuseNot affected
Red Hat Satellite 6elasticsearchNot affected
Red Hat Subscription Asset ManagerelasticsearchNot affected
Red Hat JBoss A-MQ 6.3FixedRHSA-2017:086803.04.2017
Red Hat JBoss Fuse 6.3FixedRHSA-2017:086803.04.2017

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1191969elasticsearch: remote code execution via Groovy sandbox bypass

6.5 Medium

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 11 лет назад

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVSS3: 9.8
nvd
почти 11 лет назад

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVSS3: 9.8
debian
почти 11 лет назад

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x be ...

github
больше 3 лет назад

Improper Access Control in Elasticsearch

6.5 Medium

CVSS3

6.8 Medium

CVSS2