VDB

CVE-2015-1427

CVE-2015-1427 REJECTED KEV CVSS 9.800000190734863 CRITICAL

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

EPSS 99.91% · 100.0th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
99.91%
100.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSelasticsearch1.6.2+dfsg-1, 1.7.3+dfsg-1, 1.7.3+dfsg-2

Timeline

  • CVE Published
  • Mar 9, 2015 PoC Published
  • Mar 12, 2015 PoC Published
  • Jun 26, 2015 PoC Published
  • Jan 9, 2017 VulnCheck XDB Entry
  • Apr 9, 2019 VulnCheck KEV Exploitation
  • May 20, 2019 VulnCheck KEV Exploitation
  • Jun 15, 2019 VulnCheck KEV Exploitation
  • Jul 23, 2019 VulnCheck KEV Exploitation
  • Jul 25, 2019 VulnCheck KEV Exploitation
  • Aug 28, 2019 VulnCheck KEV Exploitation
  • Sep 1, 2019 VulnCheck KEV Exploitation
Open in Interactive Console →
$ Console Community · 100/wk Open console ›