CVE-2014-4326: OS Command Injection
Published Jul 22, 2014
·Updated
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagiosnsca.rb in outputs/.
Other sources
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagiosnsca.rb in outputs/.
Affected Software
28 affected componentsFixes available
Elastic Logstash=1.0.14
Elastic Logstash=1.0.15
Elastic Logstash=1.0.16
Elastic Logstash=1.0.17
Elastic Logstash=1.1.0
Elastic Logstash=1.1.0.1
Elastic Logstash=1.1.1
Elastic Logstash=1.1.2
Elastic Logstash=1.1.3
Elastic Logstash=1.1.4
Elastic Logstash=1.1.5
Elastic Logstash=1.1.6
Elastic Logstash=1.1.7
Elastic Logstash=1.1.8
Elastic Logstash=1.1.9
Elastic Logstash=1.1.10
Elastic Logstash=1.1.11
Elastic Logstash=1.1.12
Elastic Logstash=1.1.13
Elastic Logstash=1.2.1
Elastic Logstash=1.2.2
Elastic Logstash=1.3.0
Elastic Logstash=1.3.1
Elastic Logstash=1.3.2
Elastic Logstash=1.3.3
Elastic Logstash=1.4.0
Elastic Logstash=1.4.1
rubygems/logstash>=1.0.14<1.4.2
1.4.2
Event History
Jul 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·12:58 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-4326?
The severity of CVE-2014-4326 is high due to the potential for remote command execution.
2
How do I fix CVE-2014-4326?
To fix CVE-2014-4326, upgrade Logstash to version 1.4.2 or later.
3
What versions of Logstash are affected by CVE-2014-4326?
CVE-2014-4326 affects Logstash versions 1.0.14 through 1.4.1.
4
Can CVE-2014-4326 be exploited remotely?
Yes, CVE-2014-4326 can be exploited remotely by an attacker using a crafted event.
5
What are the components impacted by CVE-2014-4326?
CVE-2014-4326 impacts the zabbix.rb and nagios_nsca.rb outputs in Logstash.