VDB
CVE-2015-1427
CVE-2015-1427
REJECTED
KEV
CVSS 9.800000190734863 CRITICAL
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
EPSS 99.91% · 100.0th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
99.91%
100.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | elasticsearch | 1.6.2+dfsg-1, 1.7.3+dfsg-1, 1.7.3+dfsg-2 |
Timeline
- CVE Published
- Mar 9, 2015 PoC Published
- Mar 12, 2015 PoC Published
- Jun 26, 2015 PoC Published
- Jan 9, 2017 VulnCheck XDB Entry
- Apr 9, 2019 VulnCheck KEV Exploitation
- May 20, 2019 VulnCheck KEV Exploitation
- Jun 15, 2019 VulnCheck KEV Exploitation
- Jul 23, 2019 VulnCheck KEV Exploitation
- Jul 25, 2019 VulnCheck KEV Exploitation
- Aug 28, 2019 VulnCheck KEV Exploitation
- Sep 1, 2019 VulnCheck KEV Exploitation
References
- Nuclei Template exploit
- https://ubuntu.com/security/CVE-2015-1427 third-party-advisory
- http://seclists.org/bugtraq/2015/Feb/92 third-party-advisory
- http://xforce.iss.net/xforce/xfdb/100850 third-party-advisory
- http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/ third-party-advisory
- http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.html third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2015-1427 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory