CVE-2015-3337
MEDIUM 4.3EPSS 32.9%
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.
- CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 32.93% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- medium · CWE-22
- Published
- 2015-05-01
- Updated
- 2024-08-06
Proof-of-concept exploits (1)
- jas502n/CVE-2015-33379★ · 2019-06-21
Nuclei templates (1)
ExploitDB entries (1)
Vulhub environments (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/elasticsearch-cve-2015-3337-lfi.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2015/CVE-2015-3337.yaml