PT-2025-19904 · Logstash · Logstash

Ismisepaul

·

Published

2025-05-06

·

Updated

2025-05-08

·

CVE-2025-37730

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Logstash (affected versions not specified)
Description The issue is related to improper certificate validation in Logstash's TCP output, which could lead to a man-in-the-middle (MitM) attack in "client" mode. This occurs because hostname verification in TCP output was not being performed when the ssl verification mode was set to full.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BIT-LOGSTASH-2025-37730
CVE-2025-37730

Affected Products

Logstash