CVE-2015-5619Improper Certificate Validation in Logstash

Severity
5.9MEDIUMNVD
EPSS
0.3%
top 46.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 9
Latest updateMay 14

Description

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDelastic/logstash1.4.0, 1.4.1, 1.4.2+2
NVDelasticsearch/logstash6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-68pf-743m-hv2w: Logstash 12022-05-14
CVEList
CVE-2015-5619: Logstash 12017-08-09
CVE-2015-5619 — Improper Certificate Validation | cvebase