Index: vuln.xml =================================================================== --- vuln.xml (revision 392885) +++ vuln.xml (working copy) @@ -58,6 +58,67 @@ --> + + elasticsearch -- directory traversal attack via snapshot API + + + elasticsearch + 1.0.01.6.1 + + + + +

Elastic reports:

+
+

Vulnerability Summary: Elasticsearch versions from 1.0.0 to 1.6.0 + are vulnerable to a directory traversal attack.

+

Remediation Summary: Users should upgrade to 1.6.1 or later, or + constrain access to the snapshot API to trusted sources.

+
+ +
+ + CVE-2015-5531 + ports/201834 + https://www.elastic.co/community/security + + + 2015-07-16 + 2015-07-25 + +
+ + + elasticsearch -- remote code execution via transport protocol + + + elasticsearch + 1.6.1 + + + + +

Elastic reports:

+
+

Vulnerability Summary: Elasticsearch versions prior to 1.6.1 are + vulnerable to an attack that can result in remote code execution.

+

Remediation Summary: Users should upgrade to 1.6.1 or 1.7.0. + Alternately, ensure that only trusted applications have access to + the transport protocol port.

+
+ +
+ + CVE-2015-5377 + ports/201834 + https://www.elastic.co/community/security + + + 2015-07-16 + 2015-07-25 + +
+ chromium -- multiple vulnerabilities