Skip to content
ElasticsearchGHSA-x8q8-4hp5-463w

Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch

MediumCVE-2015-3337 · Published May 17, 2022 · updated Dec 7, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
< 1.4.51.4.5
>= 1.5.0, < 1.5.21.5.2
Details and references

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2015-3337

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
May 172022Elasticsearch Improper Access Control vulnerability
CVE-2014-3120High8.1fixed in 1.4.0.Beta1
May 142022Cross-site scripting in Elasticsearch
CVE-2014-6439Mediumfixed in 1.4.0.Beta1
May 142022Improper Access Control in Elasticsearch
CVE-2015-1427Highfixed in 1.3.8, 1.4.3
May 142022Improper Access Control in Elasticsearch
CVE-2015-4165High7.5fixed in 1.6.0
May 142022Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
CVE-2015-5531Mediumfixed in 1.6.1
May 132022Improper Restriction of XML External Entity Reference in Elasticsearch
CVE-2018-17247Medium5.9fixed in 6.5.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.