ElasticSearch Snapshot API Directory Traversal

Discussion in 'News Aggregator' started by Packet Storm, 15 Oct 2015.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a directory traversal vulnerability in ElasticSearch, allowing an attacker to read arbitrary files with JVM process privileges, through the Snapshot API.

    Continue reading...
     

Share This Page

Loading...