CVE-2015-5531 is a directory traversal vulnerability in Elasticsearch versions prior to 1.6.1, allowing remote attackers to read arbitrary files through unspecified snapshot API calls. With a CVSS score of 5.0, it is a network-exploitable vulnerability requiring low attack complexity, potentially leading to unauthorized information disclosure. This vulnerability has high exploitability, evidenced by available Metasploit modules, Nuclei templates, and ExploitDB entries, and has garnered significant community and media attention, including reports of active exploitation against exposed Elasticsearch servers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.0CPE matchmatch criteria | cpe:2.3:a:elasticsearch:elasticsearch:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.