We found results for “”
WS-2015-0054
Good to know:
Date: September 12, 2015
Security vulnerability found in Elasticsearch before v5.0.0-alpha1. Failure to obtain a secure connection can occur due to issue within “accessClassInPackage.sun.security.ssl”.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Missing Encryption of Sensitive Data
CWE-311Top Fix
Upgrade Version
Upgrade to version org.apache.servicemix.bundles:org.apache.servicemix.bundles.elasticsearch:2.0.1_2;org.apache.servicemix.bundles:org.apache.servicemix.bundles.elasticsearch:2.1.0_2;org.apache.servicemix.bundles:org.apache.servicemix.bundles.elasticsearch:2.0.0_3;org.apache.servicemix.bundles:org.apache.servicemix.bundles.elasticsearch:2.4.3_1;org.apache.servicemix.bundles:org.apache.servicemix.bundles.elasticsearch:5.1.2_1;org.apache.servicemix.bundles:org.apache.servicemix.bundles.elasticsearch:2.0.2_2;org.apache.servicemix.bundles:org.apache.servicemix.bundles.elasticsearch:2.1.1_2
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


