CVE-2015-1427
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 9.8epss 100%
de la publicación al arma22 días
Publicada en NVD17 feb
1ª PoC+22d
metasploit11 feb
CISA KEV+2593d
probabilidad de explotación
100%top 1% de las CVE
explotación observada
síCISA + VulnCheck
11 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2022-04-15
Apply updates per vendor instructions.
Versiones
Afectadas
maven/org.elasticsearch:elasticsearch <= 1.3.7; maven/org.elasticsearch:elasticsearch >= 1.4.0, <= 1.4.2
Corregidas en
maven/org.elasticsearch:elasticsearch 1.3.8; maven/org.elasticsearch:elasticsearch 1.4.3
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
n/a · n/aPoCs públicas encontradas — 11✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/36337exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/36415githubgithub.com/t0kx/exploit-CVE-2015-1427★ 32githubgithub.com/cved-sources/cve-2015-1427★ 0githubgithub.com/cyberharsh/Groovy-scripting-engine-CVE-2015-1427★ 0githubgithub.com/xpgdgit/CVE-2015-1427★ 0githubgithub.com/Sebikea/CVE-2015-1427-for-trixie★ 0vulncheckvulncheck.com/xdb/3dcf28bea839no verificadocve_referencepacketstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.htmlno verificadovulncheckvulncheck.com/xdb/7c460955b63dno verificadocve_referencepacketstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remote-Code-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.htmlhttp://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remote-Code-Execution.htmlhttps://access.redhat.com/errata/RHSA-2017:0868https://exchange.xforce.ibmcloud.com/vulnerabilities/100850https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1427https://www.elastic.co/community/security/http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/http://www.securityfocus.com/archive/1/534689/100/0/threadedhttp://www.securityfocus.com/bid/72585