CVE-2015-5531
Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
EPSS 91.8%
描述
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.
如何修補 CVE-2015-5531
要修補 CVE-2015-5531,請將受影響套件升級到下列已修補版本。
- Maven/org.elasticsearch:elasticsearch—升級至 1.6.1 或更新版本
CVE-2015-5531 正在被利用嗎?
可能 — EPSS 為 91.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 1.6.1
參考連結(6)
- ADVISORYnvd.nist.gov/vuln/detail/CVE-2015-5531
- WEBpacketstormsecurity.com/files/132721/Elasticsearch-Directory-Traversal.html
- WEBpacketstormsecurity.com/files/133797/ElasticSearch-Path-Traversal-Arbitrary-File-Download.html
- WEBpacketstormsecurity.com/files/133964/ElasticSearch-Snapshot-API-Directory-Traversal.html