Elasticsearch before 1.4.5 and 1.5.x before 1.5.2 allows remote attackers to read arbitrary files via unspecified vectors when a site plugin is enabled.
View the template here CVE-2015-3337.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2015/CVE-2015-3337.yaml
References: