CVE-2015-1427

Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

Description

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

Severity: CRITICAL

CVSS Score: 9.8

Vendor: Elastic

Product: Elasticsearch

Loading CVE details...