Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5377

Опубликовано: 06 мар. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия до 1.6.1 (исключая)

EPSS

Процентиль: 97%
0.39895
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

redhat
больше 10 лет назад

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

CVSS3: 9.8
debian
почти 8 лет назад

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrar ...

CVSS3: 9.8
github
больше 3 лет назад

** DISPUTED ** Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability.

EPSS

Процентиль: 97%
0.39895
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74