The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
https://exchange.xforce.ibmcloud.com/vulnerabilities/100850
https://github.com/fayazmohmmand/asm-platform
https://github.com/BL3IP/port-vuln-scanner
https://github.com/Bhanunamikaze/VaktScan
https://github.com/Yamewrong/cve-lab
https://github.com/ucsb-seclab/CVEX-records
https://github.com/advisories/GHSA-w94p-6mhw-4qxw
https://github.com/h3inzzz/cve2015_1427
https://www.elastic.co/community/security/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1427
http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/