The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
| Software | From | Fixed in |
|---|---|---|
org.elasticsearch / elasticsearch
|
- | 1.3.8 |
org.elasticsearch / elasticsearch
|
1.4.0 | 1.4.3 |
| elastic / elasticsearch | 1.4.0 | 1.4.3 |
| elastic / elasticsearch | - | 1.3.8 |
| redhat / fuse | 1.0.0 | 1.0.0.x |