← back
CVE-2015-1427criticalunder attack

CVE-2015-1427

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon22 days
Published on NVDFeb 17
1st PoC+22d
metasploitFeb 11
CISA KEV+2593d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
11 public exploit(s)
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

Versions

Affected
maven/org.elasticsearch:elasticsearch <= 1.3.7; maven/org.elasticsearch:elasticsearch >= 1.4.0, <= 1.4.2
Fixed in
maven/org.elasticsearch:elasticsearch 1.3.8; maven/org.elasticsearch:elasticsearch 1.4.3
Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.