CVE-2015-3337: Path Traversal
Published May 1, 2015
·Updated
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.
Affected Software
3 affected components
Elasticsearch Elasticsearch<=1.4.4
Elasticsearch Elasticsearch=1.5.0
Elasticsearch Elasticsearch=1.5.1
Remediation
Patch Available
Event History
May 1, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3337?
CVE-2015-3337 is classified as a medium severity vulnerability that allows remote attackers to exploit directory traversal.
2
What versions are affected by CVE-2015-3337?
CVE-2015-3337 affects Elasticsearch versions before 1.4.5 and version 1.5.0 to 1.5.1.
3
How do I fix CVE-2015-3337?
To fix CVE-2015-3337, upgrade Elasticsearch to version 1.4.5 or 1.5.2 and later.
4
What type of attack does CVE-2015-3337 enable?
CVE-2015-3337 enables remote attackers to read arbitrary files on the server via directory traversal.
5
Is CVE-2015-3337 related to site plugins in Elasticsearch?
Yes, CVE-2015-3337 specifically affects Elasticsearch when a site plugin is enabled.