CVE-2015-5531
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 95%
from disclosure to weapon46 days
Published on NVDAug 17
1st PoC+46d
VulnCheck+3571d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesVulnCheck
10 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Not affected
2 products — because the vulnerable code is not present in the product
Red Hat Satellite 6 · Red Hat Subscription Asset Manager
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.
Affected products
n/a · n/apublic PoCs found — 10
exploitdbwww.exploit-db.com/exploits/38383unverifiedgithubgithub.com/MoCh3n/CVE-2015-5531-POC★ 2githubgithub.com/xpgdgit/CVE-2015-5531★ 0cve_referencepacketstormsecurity.com/files/133964/ElasticSearch-Snapshot-API-Directory-Traversal.htmlunverifiedcve_referencewww.exploit-db.com/exploits/38383/unverifiedcve_referencepacketstormsecurity.com/files/133797/ElasticSearch-Path-Traversal-Arbitrary-File-Download.htmlunverifiedcve_referencepacketstormsecurity.com/files/132721/Elasticsearch-Directory-Traversal.htmlunverifiedvulncheckvulncheck.com/xdb/6afe112371ffunverifiedvulncheckvulncheck.com/xdb/bf7c15878cf8unverifiedvulncheckvulncheck.com/xdb/e443d0f06ef7unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/132721/Elasticsearch-Directory-Traversal.htmlhttp://packetstormsecurity.com/files/133797/ElasticSearch-Path-Traversal-Arbitrary-File-Download.htmlhttp://packetstormsecurity.com/files/133964/ElasticSearch-Snapshot-API-Directory-Traversal.htmlhttps://www.elastic.co/community/security/https://www.exploit-db.com/exploits/38383/http://www.securityfocus.com/archive/1/536017/100/0/threadedhttp://www.securityfocus.com/bid/75935