Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:1493
HistoryFeb 18, 2015 - 5:22 p.m.

Arbitrary Shell Command Execution In The Groovy Scripting Engine

2015-02-1817:22:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
237

0.874 High

EPSS

Percentile

98.7%

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CPENameOperatorVersion
serverle1.3.7
serverle1.4.2
elasticsearcheq1.4.2