Back

MEDIUM

elasticsearch: directory traversal flaw

Published May 1, 2015

Description

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

Affected products

Remediation

Red Hat statement

This issue affects the versions of elasticsearch as shipped with Red Hat Satellite 6.x and Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Red Hat mitigation

Users that do not want to upgrade can address the vulnerability in several ways, but these options will break any site plugin: * Set http.disable_sites to true in the elasticsearch.yml config file on any node with a site plugin, and restart the Elasticsearch node. * Use a firewall or proxy to block HTTP requests to /_plugin. * Uninstall all site plugins from all Elasticsearch nodes. For Satellite 6.x and Sam 1.x you can simply firewall elasticsearch to trusted users only (e.g. root, katello, foreman). For instructions on this please see: https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/6.0/html-single/Installation_Guide/index.html#sect-Red_Hat_Satellite-Installation_Guide-Red_Hat_Satellite_Installation-Configuring_Red_Hat_Satellite_Manually

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 1, 2015
Updated Aug 6, 2024
Reserved Apr 20, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 24, 2015
GHSA-X8Q8-4HP5-463W