Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-5377

Опубликовано: 06 мар. 2018
Источник: debian
EPSS Средний

Описание

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elasticsearchfixed1.6.1+dfsg-1package
elasticsearchend-of-lifejessiepackage

Примечания

  • https://www.elastic.co/blog/elasticsearch-1-7-0-and-1-6-1-released#security

EPSS

Процентиль: 97%
0.39895
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

redhat
больше 10 лет назад

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

CVSS3: 9.8
nvd
почти 8 лет назад

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

CVSS3: 9.8
github
больше 3 лет назад

** DISPUTED ** Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability.

EPSS

Процентиль: 97%
0.39895
Средний