CVE-2015-1427

Publication date

2015-02-17 15:00:00

Family

mitre

State

PUBLISHED

Description

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.