{
  "threat_severity" : "Low",
  "public_date" : "2015-04-24T00:00:00Z",
  "bugzilla" : {
    "description" : "elasticsearch: directory traversal flaw",
    "id" : "1216014",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1216014"
  },
  "cvss" : {
    "cvss_base_score" : "1.9",
    "cvss_scoring_vector" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-22",
  "details" : [ "Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors." ],
  "statement" : "This issue affects the versions of elasticsearch as shipped with Red Hat Satellite 6.x and Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.",
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Enterprise 2",
    "fix_state" : "Under investigation",
    "package_name" : "openshift-origin-cartridge-fuse",
    "cpe" : "cpe:/a:redhat:openshift:2"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Under investigation",
    "package_name" : "elasticsearch",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Subscription Asset Manager",
    "fix_state" : "Under investigation",
    "package_name" : "elasticsearch",
    "cpe" : "cpe:/a:rhel_sam:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2015-3337\nhttps://nvd.nist.gov/vuln/detail/CVE-2015-3337" ],
  "name" : "CVE-2015-3337",
  "mitigation" : {
    "value" : "Users that do not want to upgrade can address the vulnerability in several ways, but these options will break any site plugin:\n* Set http.disable_sites to true in the elasticsearch.yml config file on any node with a site plugin, and restart the Elasticsearch node.\n* Use a firewall or proxy to block HTTP requests to /_plugin.\n* Uninstall all site plugins from all Elasticsearch nodes.\nFor Satellite 6.x and Sam 1.x you can simply firewall elasticsearch to trusted users only (e.g. root, katello, foreman). For instructions on this please see:\nhttps://access.redhat.com/documentation/en-US/Red_Hat_Satellite/6.0/html-single/Installation_Guide/index.html#sect-Red_Hat_Satellite-Installation_Guide-Red_Hat_Satellite_Installation-Configuring_Red_Hat_Satellite_Manually",
    "lang" : "en:us"
  },
  "csaw" : false
}