Vulnerabilities
Vulnerable Software
Elastic:  >> Logstash  >> 6.1.3  Security Vulnerabilities
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop responding.
CVSS Score
7.5
EPSS Score
0.014
Published
2019-10-30
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-03-25


Contact Us

Shodan ® - All rights reserved