Disclosure summary
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
CISA remediation guidance
Apply updates per vendor instructions.
Original records & references
PUBLISHED 2022-03-25T00:00:00-04:00
MODIFIED 2022-03-25T00:00:00-04:00
INGESTED 2026-10-06T11:42:58-04:00