CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2015-1427

CVSS 9.8v3.1pub. 2015-02-17upd. 2026-04-22

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Elastic Elasticsearch

    APP
    Elastic
    < 1.3.81.4.0 – 1.4.3 (excl.)
  • Red Hat Fuse

    APP
    Redhat
    1.0.0

CISA KEV — detailsi

Vendori
Elastic
Producti
Elasticsearch
Added to KEVi
March 25, 2022
Remediation deadline (US Federal)i
April 15, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 15 kwietnia 2022
CWE
References

Related vulnerabilities

CVE-2016-4437CRITICAL9.8⚠ KEVPL ✓same product

Apache Shiro RCE przez nieskonfigurowany klucz szyfrowania 'remember me'

CVE-2025-12543CRITICAL9.6PL ✓same product

Brak walidacji nagłówka Host w serwerze Undertow HTTP

CVE-2018-1270CRITICAL9.8PL ✓same product

RCE w Spring Framework przez STOMP over WebSocket (spring-messaging)

CVE-2015-5377CRITICAL9.8PL ✓same product

RCE w Elasticsearch przez protokół transportowy (przed wersją 1.6.1)

CVE-2017-5645CRITICAL9.8PL ✓same product

Apache Log4j 2.x — RCE poprzez deserializację zdarzeń przez socket server