CVE-2019-7613Insufficient Logging in Winlogbeat

Severity
7.5HIGHNVD
EPSS
0.2%
top 60.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 13

Description

Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDelastic/winlogbeat6.0.06.6.2+1
CVEListV5elastic/logstashbefore 5.6.16 and 6.6.2

🔴Vulnerability Details

2
GHSA
GHSA-2mc6-hfwx-q7vw: Winlogbeat versions before 52022-05-13
CVEList
CVE-2019-7613: Winlogbeat versions before 52019-03-25
CVE-2019-7613 — Insufficient Logging in Elastic | cvebase