Vulnerabilities
Vulnerable Software
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability
CVSS Score
9.8
EPSS Score
0.4
Published
2018-03-06
CVE-2015-1427
Known exploited
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
CVSS Score
9.8
EPSS Score
0.939
Published
2015-02-17


Contact Us

Shodan ® - All rights reserved