Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3337

Опубликовано: 24 апр. 2015
Источник: redhat
CVSS2: 1.9
EPSS Критический

Описание

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

Отчет

This issue affects the versions of elasticsearch as shipped with Red Hat Satellite 6.x and Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Users that do not want to upgrade can address the vulnerability in several ways, but these options will break any site plugin:

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1amq-6Under investigation
Red Hat JBoss Enterprise Web Server 1fuse-6Under investigation
Red Hat JBoss Enterprise Web Server 1fuse-amq-7Under investigation
Red Hat JBoss Enterprise Web Server 1fuse-esb-7Under investigation
Red Hat OpenShift Enterprise 2openshift-origin-cartridge-fuseUnder investigation
Red Hat Satellite 6elasticsearchUnder investigation
Red Hat Subscription Asset ManagerelasticsearchUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1216014elasticsearch: directory traversal flaw

EPSS

Процентиль: 100%
0.90729
Критический

1.9 Low

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

nvd
почти 11 лет назад

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

debian
почти 11 лет назад

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1. ...

github
больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch

EPSS

Процентиль: 100%
0.90729
Критический

1.9 Low

CVSS2