5.9

CVE-2015-5619

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elastic ≫ Logstash Version 1.4.0
Elastic ≫ Logstash Version 1.4.1
Elastic ≫ Logstash Version 1.4.2
Elasticsearch ≫ Logstash Version 1.4.3
Elasticsearch ≫ Logstash Version 1.4.4
Elasticsearch ≫ Logstash Version 1.5.0
Elasticsearch ≫ Logstash Version 1.5.1
Elasticsearch ≫ Logstash Version 1.5.2
Elasticsearch ≫ Logstash Version 1.5.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.22% 0.647
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

http://packetstormsecurity.com/files/133269/Logstash-1.5.3-Man-In-The-Middle.html
Third Party Advisory
VDB Entry
http://www.securityfocus.com/archive/1/536294/100/0/threaded
http://www.securityfocus.com/archive/1/536858/100/0/threaded
http://www.securityfocus.com/bid/76455
Third Party Advisory
VDB Entry
https://www.elastic.co/blog/logstash-1-5-4-and-1-4-5-released
Vendor Advisory