# Groovy scripting vulnerability

**URL:** <https://discuss.elastic.co/t/groovy-scripting-vulnerability/22104>\
**Category:** Elasticsearch\
**Created:** [February 11, 2015, 6:21pm UTC](https://discuss.elastic.co/t/groovy-scripting-vulnerability/22104 "2015-02-11T18:21:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticSearch\_Users\_](https://avatars.discourse-cdn.com/v4/letter/e/b4bc9f/32.png) [@ElasticSearch\_Users\_](https://discuss.elastic.co/u/ElasticSearch_Users_)\
**Post date:** [February 11, 2015, 6:21pm UTC](https://discuss.elastic.co/t/groovy-scripting-vulnerability/22104/1 "2015-02-11T18:21:26Z")

</div>

Hi all

Elasticsearch versions 1.3.0-1.3.7 and 1.4.0-1.4.2 have a vulnerability in  
the Groovy scripting engine. The vulnerability allows an attacker to  
construct Groovy scripts that escape the sandbox and execute shell commands  
as the user running the Elasticsearch Java VM.

We have released Elasticsearch 1.3.8 and 1.4.3 to address this issue.  
Please read the blogpost and either upgrade or update your config to  
disable dynamic Groovy scripting:

> **[Elasticsearch 1.4.3 and 1.3.8 Released
	  	 | Elastic](https://www.elastic.co/blog/elasticsearch-1-4-3-and-1-3-8-released)**
>
> Today, we have released the security and bug fix release of Elasticsearch 1.4.3, based on Lucene 4.10.3, and Elasticsearch 1.3.8. You can download them and read the full changes list here: Latest...

thanks

Clint

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/cb811038-becb-45a6-bff7-c268d4e3fd78%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cb811038-becb-45a6-bff7-c268d4e3fd78%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:33am UTC](https://discuss.elastic.co/t/groovy-scripting-vulnerability/22104/2 "2017-07-06T00:33:26Z")

</div>


