SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Elastic Elasticsearch Insecure Deserialization

Category: MISC      

Elasticsearch versions prior to 1.6.1 are vulnerable to an engineered attack on its transport protocol that enables remote code execution. This issue is related to the Groovy announcement in CVE-2015-3253.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5377


Relevant Information