Elasticsearch before 1.4.5 and 1.5.x before 1.5.2 allows remote attackers to read arbitrary files via unspecified vectors when a site plugin is enabled.
id: CVE-2015-3337
info:
name: Elasticsearch - Local File Inclusion
author: pdteam
severity: m
...