CVE-2015-1427 | Elasticsearch 1.3.7/1.4.0/1.4.1/1.4.2 Groovy Scripting Engine access control (RHSA-2017:0868 / EDB-36337)
A vulnerability was found in Elasticsearch 1.3.7/1.4.0/1.4.1/1.4.2. It has been rated as critical. This issue affects some unknown processing of the component Groovy Scripting Engine. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2015-1427. The attack can be initiated remotely. Additionally, an exploit exists.
Upgrading the affected component is advised.