CVE-2015-5377

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

History

07 Nov 2023, 02:26

Type Values Removed Values Added
Summary ** DISPUTED ** Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability. Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

Information

Published : 2018-03-06 20:29

Updated : 2024-08-06 07:15


NVD link : CVE-2015-5377

Mitre link : CVE-2015-5377

CVE.ORG link : CVE-2015-5377


JSON object : View

Products Affected

elastic

  • elasticsearch
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')