Loading
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
Use Elastic vendor hub and Elasticsearch product page to widen CVE-2015-1427 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-37731, CVE-2025-68384 and CVE-2024-52979 for nearby disclosures in the same product family.