CVE-2015-3337 | Elasticsearch up to 1.4.4/1.5.1 Site Plugin path traversal (ID 131646 / EDB-37054)
A vulnerability was found in Elasticsearch up to 1.4.4/1.5.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Site Plugin. The manipulation leads to path traversal.
This vulnerability is known as CVE-2015-3337. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.