CVE-2015-5378: Infoleak
Published Jun 27, 2017
·Updated
Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.
Affected Software
7 affected components
Elastic Logstash=1.4.0
Elastic Logstash=1.4.1
Elastic Logstash=1.4.2
Elasticsearch Logstash=1.4.3
Elasticsearch Logstash=1.5.0
Elasticsearch Logstash=1.5.1
Elasticsearch Logstash=1.5.2
Event History
Jun 27, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5378?
CVE-2015-5378 is considered to have a medium severity level due to its potential for remote information disclosure.
2
How do I fix CVE-2015-5378?
To mitigate CVE-2015-5378, upgrade Logstash to version 1.5.3 or later.
3
What versions are affected by CVE-2015-5378?
CVE-2015-5378 affects Logstash versions 1.5.0 through 1.5.2 and 1.4.0 through 1.4.3.
4
What type of attack does CVE-2015-5378 allow?
CVE-2015-5378 allows remote attackers to read unencrypted communications between the Logstash Forwarder agent and Logstash server.
5
Is CVE-2015-5378 a local or remote vulnerability?
CVE-2015-5378 is a remote vulnerability that can be exploited by attackers from outside the network.