VYPR
Moderate severityNVD Advisory· Published May 1, 2015· Updated May 6, 2026

CVE-2015-3337

CVE-2015-3337

Description

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.elasticsearch:elasticsearchMaven
< 1.4.51.4.5
org.elasticsearch:elasticsearchMaven
>= 1.5.0, < 1.5.21.5.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.