CVE-2015-1427 is a sandbox-bypass vulnerability in Elasticsearch's Groovy scripting engine affecting versions before 1.3.8 and the 1.4.x branch before 1.4.3. A remote attacker can submit a crafted script that escapes sandbox restrictions and executes arbitrary operating-system commands. A demonstrated technique uses Java reflection to load java.lang.Runtime indirectly and invoke exec().
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a deliberately vulnerable Elasticsearch training lab with valid exploit payloads documented in app/README.md and its Chinese translation, rather than a standalone automated exploit tool. The walkthrough creates an indexed document and submits a Groovy script_fields search request to escape the sandbox, execute id and return its output. It documents both a Java-reflection/Runtime technique and a direct Groovy execute() variant. CVE-2015-1427 is the target; CVE-2014-3120 appears only as historical context. The documentation identifies 1.3.8 and 1.4.3 as fixed releases, while the supplied lab specifically runs 1.4.2. The 33 files include vendored Vulhub walkthroughs and Compose configuration under app/, a Dockerfile, entrypoint and logging configuration under base/elasticsearch/1.4.2/, the central isoloom.yml specification, and generated deployment outputs under .isoloom/. These outputs support Docker, Kubernetes, Vagrant-hosted Docker, Proxmox-hosted Docker and six cloud providers: AWS, Azure, DigitalOcean, GCP, Linode and OCI. GitHub workflows validate and publish the lab. The 15 code/build/IaC files comprise seven Terraform files, one Ruby Vagrantfile, six shell scripts and one Dockerfile; YAML deployment files and workflow-embedded commands are additional infrastructure content. Groovy exploit code exists inside Markdown documentation. The checks verify HTTP availability, the reported 1.4.2 version and blocked Internet access; they do not exercise the sandbox bypass or prove successful exploitation. Docker isolation removes the target's default route, while Kubernetes uses network policies whose enforcement depends on the cluster networking implementation. Cloud firewalls restrict inbound SSH and published ports to an operator-provided CIDR, but Kubernetes supplies a LoadBalancer service with unrestricted source ingress on 9200 and 9300. The legacy app Compose file also publishes both ports without the generated isolation controls. No callback, exfiltration, persistence or container-escape mechanism is present. Cleanup commands in provisioning and CI have ordinary lab-management purposes and do not indicate a fake exploit. The default deployment pulls vulhub/elasticsearch:1.4.2 by tag; the vendored build recipe is not used automatically and relies on historical download sources. Analysis is static and does not establish runtime success. The original analyzed repository URL, analyzed git reference and archive size were not supplied; empty strings and zero represent unavailable metadata. The documented Vulhub commit 8fd63916f7a8711e2e01dda0d27237e4d6175d38 identifies upstream provenance, not the analyzed repository reference.
This repository contains a single Metasploit module targeting ElasticSearch servers vulnerable to CVE-2015-1427 (Groovy sandbox bypass, RCE). The exploit abuses the REST API (default port 9200) to send a specially crafted search request containing Groovy code, which bypasses the sandbox and allows arbitrary Java code execution. The module determines the target's OS and temporary directory, writes a base64-encoded Java payload (typically a Meterpreter shell) to a temporary file, and loads it via a URLClassLoader. The exploit is weaponized, allowing the attacker to select and deliver any Metasploit Java payload. The only code file is a Ruby Metasploit module, and the main attack vector is network-based, targeting the unauthenticated ElasticSearch REST API. The endpoints of interest are the REST API URL (http://<target>:9200/_search) and the temporary file path used for payload delivery.
This repository provides a proof-of-concept exploit for CVE-2015-1427, a remote code execution vulnerability in Elasticsearch versions 1.4.0 to 1.4.2. The repository includes a Dockerfile to set up a vulnerable Elasticsearch environment, a main.sh script to initialize the service and add sample data, and an exploit.sh script that performs the actual exploit. The exploit works by sending a specially crafted Groovy script via the Elasticsearch REST API (typically on port 9200), which bypasses the Groovy sandbox and executes arbitrary system commands (demonstrated with 'whoami'). The exploit does not require authentication and targets the default REST API endpoint. The repository is structured for easy testing and demonstration of the vulnerability, making it suitable for educational and research purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Elasticsearch's Groovy scripting sandbox that can be bypassed using Java reflection to reach `Runtime.exec()`.
A Groovy scripting sandbox escape in Elasticsearch that allows remote attackers to execute arbitrary shell commands using a crafted script. Affected versions are those before 1.3.8 and the 1.4.x branch before 1.4.3. The record references public remote-code-execution exploit material and fixed-version releases.
A remote code execution vulnerability in Elasticsearch due to Groovy scripting sandbox bypass, allowing attackers to execute arbitrary code.
A remote code execution vulnerability in ElasticSearch cited as another flaw used by z0Miner.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.