VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Feb 17, 2015· Updated Apr 22, 2026

CVE-2015-1427

CVE-2015-1427

Description

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.elasticsearch:elasticsearchMaven
< 1.3.81.3.8
org.elasticsearch:elasticsearchMaven
>= 1.4.0, < 1.4.31.4.3

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.