HomeElasticCVE-2015-1427

CVE-2015-1427

CRITICAL
9.8CVSS
Published: 2015-02-17
Updated: 2025-10-22
AI Analysis

Description

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
NVD-CWE-noinfo

Metadata

Primary Vendor
ELASTIC
Published
2/17/2015
Last Modified
10/22/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

elastic : elasticsearchelastic : elasticsearchredhat : fuse

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2015-1427 | CRITICAL Severity | CVEDatabase.com | CVEDatabase.com