Elasticsearch 5 is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
id: elasticsearch5-log4j-rce
info:
name: Elasticsearch 5 - Remote Code Execution (Apache Log4j)
...