The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
Source: NVD ↗ · CISA KEV Catalog ↗