ElasticsearchGHSA-w94p-6mhw-4qxw
Improper Access Control in Elasticsearch
HighCVE-2015-1427 · Published May 14, 2022 · updated Dec 5, 2024
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | < 1.3.8 | 1.3.8 |
| >= 1.4.0, < 1.4.3 | 1.4.3 |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-284
- Also known as
- CVE-2015-1427
- nvd.nist.gov/vuln/detail/CVE-2015-1427
- access.redhat.com/errata/RHSA-2017:0868
- exchange.xforce.ibmcloud.com/vulnerabilities/100850
- www.elastic.co/community/security
- packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.html
- packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remote-Code-Execution.html
- www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 142022 | Cross-site scripting in Elasticsearch | Medium | 1.4.0.Beta1 |
| May 142022 | Improper Access Control in Elasticsearch | High7.5 | 1.6.0 |
| May 142022 | Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch | Medium | 1.6.1 |
| May 132022 | Improper Restriction of XML External Entity Reference in Elasticsearch | Medium5.9 | 6.5.2 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch | Medium6.5 | 6.4.3 |
| May 132022 | Elasticsearch subject to cross site scripting | Medium6.1 | 5.6.9+1 more |