CVE-2015-1427

⚠ KEVEPSS 92.3%

Improper Access Control in Elasticsearch

發布日:2022/5/14修改日:2024/12/5加入 CISA KEV 日:2022/3/25

描述

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

受影響套件(1)

參考連結(7)