Elasticsearch Head plugin LFI

By
Sooraj V Nair
Published on
01 Oct 2021
Vulnerability

When a site plugin is activated, a directory traversal issue in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2 allows remote attackers to access arbitrary files via undefined vectors.

Mitigation / Precaution

In order to patch this vulnerability, we suggest you update Elasticsearch to the latest version


Written by
Sooraj V Nair
Sooraj V Nair
Cyber Security Engineer
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days