Elasticsearch before 1.4.5 and 1.5.x before 1.5.2 allows remote attackers to read arbitrary files via unspecified vectors when a site plugin is enabled.
View the template here CVE-2015-3337.yaml
References:
https://www.exploit-db.com/exploits/37054/