Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-5377

Опубликовано: 06 мар. 2018
Источник: debian

Описание

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elasticsearchfixed1.6.1+dfsg-1package
elasticsearchend-of-lifejessiepackage

Примечания

  • https://www.elastic.co/blog/elasticsearch-1-7-0-and-1-6-1-released#security

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

redhat
около 11 лет назад

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

CVSS3: 9.8
nvd
больше 8 лет назад

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

CVSS3: 9.8
github
больше 4 лет назад

** DISPUTED ** Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability.