Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-3337

45
FAUCET Score

CVE-2015-3337 is a directory traversal vulnerability affecting Elasticsearch versions prior to 1.4.5 and 1.5.x before 1.5.2, specifically when a site plugin is enabled. This flaw allows remote attackers to read arbitrary files. With a CVSS score of 4.3 (medium severity), this vulnerability has a network attack vector, medium attack complexity, and a potential impact of partial confidentiality loss. Its high EPSS score of 0.91113 indicates a significant likelihood of exploitation. While not listed on the CISA KEV catalog, public exploit code exists, including a Nuclei template for local file inclusion and an ExploitDB entry. Despite this, there is no recorded social media discussion or media coverage, suggesting limited public attention.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.4.4CPE matchmatch criteria
cpe:2.3:a:elasticsearch:elasticsearch:*:*:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:elasticsearch:elasticsearch:1.5.0:*:*:*:*:*:*:*
1.5.1CPE matchmatch criteria
cpe:2.3:a:elasticsearch:elasticsearch:1.5.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
33.13%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Nuclei: CVE-2015-3337 · Mar 25, 2021
ExploitDB: EDB-37054 · May 18, 2015
This CVE's current EPSS score of 0.3313 is in the 99th percentile among its peer group of 19,953 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

mavenpatch availablevia ghsa
Product: org.elasticsearch:elasticsearchFixed in: 1.4.5
mavenpatch availablevia ghsa
Product: org.elasticsearch:elasticsearchFixed in: 1.5.2
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: openshift-origin-cartridge-fuse
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: elasticsearch
redhatvendor investigatingvia redhat_api
Product: Red Hat Subscription Asset ManagerFixed in: elasticsearch

Vendor Advisories (2)

mavenGHSA-x8q8-4hp5-463wmedium

Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch

May 17, 2022
redhatCVE-2015-3337Low

elasticsearch: directory traversal flaw

Apr 24, 2015

References

packetstormsecurity.com / files/131646/Elasticsearch-Directory-Traversal.html
elastic.co / community/security
PatchVendor Advisory
exploit-db.com / exploits/37054
Exploit
debian.org / security/2015/dsa-3241
securityfocus.com / archive/1/535385
securityfocus.com / bid/74353
Exploit