A vulnerability has been reported in Elasticsearch, which can be exploited by malicious people to disclose potentially sensitive information.
Certain unspecified input is not properly verified before being used to read files. This can be exploited to disclose the contents of arbitrary local files via directory traversal sequences.
Successful exploitation requires a "site plugin" is enabled.
The vulnerability is reported in versions prior to 1.5.2 and 1.4.5.