PT-2017-6846 · Elastic · Logstash

Published

2017-06-27

·

Updated

2019-06-17

·

CVE-2015-5378

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Logstash versions 1.4.x through 1.4.3 Logstash versions 1.5.x through 1.5.2
Description The issue allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.
Recommendations For Logstash versions 1.4.x through 1.4.3, update to version 1.4.4 or later. For Logstash versions 1.5.x through 1.5.2, update to version 1.5.3 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5378

Affected Products

Logstash