CVE-2015-5378Sensitive Information Exposure in Logstash

Severity
7.5HIGHNVD
EPSS
0.7%
top 28.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateMay 14

Description

Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDelastic/logstash1.4.0, 1.4.1, 1.4.2+2
NVDelasticsearch/logstash4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-g6rc-3fpq-w2gr: Logstash 12022-05-14
CVEList
CVE-2015-5378: Logstash 12017-06-27
CVE-2015-5378 — Sensitive Information Exposure | cvebase