Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-1427

Опубликовано: 17 фев. 2015
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 7.5
CVSS3: 9.8

Описание

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

РелизСтатусПримечание
artful

ignored

end of life
bionic

DNE

devel

DNE

esm-apps/xenial

not-affected

1.7.3+dfsg-3
esm-infra-legacy/trusty

DNE

lucid

DNE

precise

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

EPSS

Процентиль: 100%
0.92326
Критический

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
почти 11 лет назад

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVSS3: 9.8
nvd
почти 11 лет назад

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVSS3: 9.8
debian
почти 11 лет назад

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x be ...

github
больше 3 лет назад

Improper Access Control in Elasticsearch

EPSS

Процентиль: 100%
0.92326
Критический

7.5 High

CVSS2

9.8 Critical

CVSS3