The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HElastic Elasticsearch
APPElastic< 1.3.81.4.0 – 1.4.3 (excl.)Red Hat Fuse
APPRedhat1.0.0
CISA KEV — detailsi
- Vendori
- Elastic
- Producti
- Elasticsearch
- Added to KEVi
- March 25, 2022
- Remediation deadline (US Federal)i
- April 15, 2022(overdue)
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 15 kwietnia 2022
References
Related vulnerabilities
CVE-2016-4437CRITICAL9.8⚠ KEVPL ✓same product
Apache Shiro RCE przez nieskonfigurowany klucz szyfrowania 'remember me'
CVE-2025-12543CRITICAL9.6PL ✓same product
Brak walidacji nagłówka Host w serwerze Undertow HTTP
CVE-2018-1270CRITICAL9.8PL ✓same product
RCE w Spring Framework przez STOMP over WebSocket (spring-messaging)
CVE-2015-5377CRITICAL9.8PL ✓same product
RCE w Elasticsearch przez protokół transportowy (przed wersją 1.6.1)
CVE-2017-5645CRITICAL9.8PL ✓same product
Apache Log4j 2.x — RCE poprzez deserializację zdarzeń przez socket server