CVE-2015-5531: Path Traversal
Published Aug 17, 2015
·Updated
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.
Affected Software
1 affected component
Elasticsearch Elasticsearch<=1.6.0
Event History
Aug 17, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5531?
CVE-2015-5531 is considered to be of high severity due to its potential for unauthorized file access.
2
How do I fix CVE-2015-5531?
To fix CVE-2015-5531, upgrade Elasticsearch to version 1.6.1 or later.
3
What types of systems are affected by CVE-2015-5531?
CVE-2015-5531 affects all versions of Elasticsearch prior to 1.6.1.
4
What could an attacker achieve with CVE-2015-5531?
An attacker could exploit CVE-2015-5531 to read arbitrary files on the server using snapshot API calls.
5
Is there any workaround for CVE-2015-5531?
There are no known workarounds for CVE-2015-5531, so updating is the only effective solution.