module

ElasticSearch Search Groovy Sandbox Bypass

Disclosed
2015-02-11
Created
2018-05-30

Description

This module exploits a remote command execution (RCE) vulnerability in ElasticSearch,
exploitable by default on ElasticSearch prior to 1.4.3. The bug is found in the
REST API, which does not require authentication, where the search function allows
groovy code execution and its sandbox can be bypassed using java.lang.Math.class.forName
to reference arbitrary classes. It can be used to execute arbitrary Java code. This
module has been tested successfully on ElasticSearch 1.4.2 on Ubuntu Server 12.04.

Authors

Cameron Morris
Darren Martyn
juan vazquez juan.vazquez@metasploit.com

Platform

Java

Architectures

java

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/multi/elasticsearch/search_groovy_script
msf exploit(search_groovy_script) > show targets
...targets...
msf exploit(search_groovy_script) > set TARGET < target-id >
msf exploit(search_groovy_script) > show options
...show and set options...
msf exploit(search_groovy_script) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.