CVE-2016-1000221
published 2017-06-16CVE-2016-1000221: Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.76%
75.3th percentile
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| elastic | logstash | <= 2.3.3 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Logstash Logs Sensitive Information
osv·2022-05-14
CVE-2016-1000221 [HIGH] Logstash Logs Sensitive Information
Logstash Logs Sensitive Information
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.
GHSA
Logstash Logs Sensitive Information
ghsa·2022-05-14
CVE-2016-1000221 [HIGH] CWE-200 Logstash Logs Sensitive Information
Logstash Logs Sensitive Information
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-06-16
Published