CVE-2015-1427
Improper Access Control in Elasticsearch
⚠ KEVEPSS 99.9%
描述
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
如何修補 CVE-2015-1427
要修補 CVE-2015-1427,請將受影響套件升級到下列已修補版本。
- Maven/org.elasticsearch:elasticsearch—升級至 1.3.8 或更新版本
CVE-2015-1427 正在被利用嗎?
是 — CVE-2015-1427 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(1)
- from 0, < 1.3.8
參考連結(7)
- ADVISORYnvd.nist.gov/vuln/detail/CVE-2015-1427
- WEBpacketstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.html
- WEBpacketstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remote-Code-Execution.html
- WEBwww.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released