Impact
Elastic Maps Server includes a path traversal vulnerability identified as CWE‑22 that allows an unauthenticated network attacker to request files outside the intended content directory. The flaw is caused by improper limitation of a pathname to a restricted directory, enabling the server process to return the contents of any readable file on the host. This can lead to the disclosure of sensitive configuration data, private keys, or other confidential information stored on the server.
Affected Systems
Affected systems are Elastic Maps Server deployments from Elastic. No specific version numbers are listed in the CNA data, so any installation of Elastic Maps Server could be vulnerable until a fix is released.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as medium impact, and the EPSS score is not available, suggesting limited known exploitation. The vulnerability is not recorded in the CISA KEV catalog, indicating no publicly known exploits at the time of reporting. The attack scenario requires an unauthenticated attacker able to reach the service over the network; the path traversal can be executed by simply manipulating request parameters. While the risk is moderate, organizations running the exposed service should address it promptly through patching or other controls.
OpenCVE Enrichment