Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3337

Опубликовано: 01 мая 2015
Источник: debian

Описание

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elasticsearchfixed1.0.3+dfsg-7package

Примечания

  • https://www.elastic.co/blog/elasticsearch-1-5-2-and-1-4-5-released

Связанные уязвимости

ubuntu
почти 11 лет назад

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

redhat
почти 11 лет назад

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

nvd
почти 11 лет назад

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

github
больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch