漏洞描述 Elasticsearch是荷兰Elasticsearch公司的一套基于Lucene构建的开源分布式RESTful搜索引擎,它主要用于云计算中,并支持通过HTTP使用JSON进行数据索引。Elasticsearch1.6.1之前版本中存在目录遍历漏洞。远程攻击者可借助快照的API调用利用该漏洞读取任意文件。如存在该漏洞,请前往https://www.elastic.co/community/security/获取最新补丁信息。
相关漏洞推荐 POC CVE-2014-3120: ElasticSearch v1.1.1/1.2 RCE POC CVE-2015-1427: ElasticSearch - Remote Code Execution POC CVE-2015-3337: Elasticsearch - Local File Inclusion POC CVE-2015-5531: ElasticSearch <1.6.1 - Local File Inclusion POC CVE-2021-22145: Elasticsearch 7.10.0-7.13.3 - Information Disclosure POC CVE-2014-3120: ElasticSearch v1.1.1/1.2 RCE POC CVE-2015-1427: ElasticSearch - Remote Code Execution POC CVE-2015-3337: Elasticsearch File Read POC CVE-2015-5531: Elasticsearch CVE-2015-5531 POC CVE-2021-22145: ElasticSearch 7.13.3 - Memory disclosure POC elasticsearch-unauth: ElasticSearch Information Disclosure POC elasticsearch-default-login: ElasticSearch - Default Login POC elasticsearch: ElasticSearch Information Disclosure