UNKNOWNKNOWN EXPLOITED
CVE-2015-1427
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
Summary
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
References
Includes data from the CISA Known Exploited Vulnerabilities catalog.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.