CVE-2015-5619: Medium severity logstash management api vulnerability
Published Aug 9, 2017
·Updated
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.
Affected Software
9 affected components
Elastic Logstash=1.4.0
Elastic Logstash=1.4.1
Elastic Logstash=1.4.2
Elasticsearch Logstash=1.4.3
Elasticsearch Logstash=1.4.4
Elasticsearch Logstash=1.5.0
Elasticsearch Logstash=1.5.1
Elasticsearch Logstash=1.5.2
Elasticsearch Logstash=1.5.3
Event History
Aug 9, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5619?
CVE-2015-5619 has a medium severity rating due to the risk of man-in-the-middle attacks.
2
How do I fix CVE-2015-5619?
To fix CVE-2015-5619, upgrade Logstash to version 1.4.5 or 1.5.4 or later.
3
What versions of Logstash are affected by CVE-2015-5619?
Versions of Logstash prior to 1.4.5 and 1.5.4 are affected by CVE-2015-5619.
4
What is the nature of the vulnerability in CVE-2015-5619?
CVE-2015-5619 involves Logstash failing to validate SSL/TLS certificates, allowing potential exposure to man-in-the-middle attacks.
5
Is CVE-2015-5619 a critical vulnerability?
CVE-2015-5619 is not classified as critical but poses significant risk due to sensitive information exposure.