Loading vulnerability details...
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
This critical vulnerability poses an immediate and severe threat to system security. Exploitation could lead to complete system compromise, data breach, or denial of service. Immediate action is required.
Listed in the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild.
Probability of exploitation in the next 30 days · more likely than 100.0% of all CVEs.
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior