Elasticsearch.Site.Plugin.Directory.Traversal

description-logoDescription

This indicates an attack attempt against a Directory Traversal vulnerability in ElasticSearch.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application while handling maliciously crafted requests. A remote attacker can exploit this to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server.

affected-products-logoAffected Products

ElasticSearch 1.4.x before 1.4.5
ElasticSearch 1.5.x before 1.5.2

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://www.elastic.co/downloads/elasticsearch

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)