CVE-2016-1000221: Infoleak
Published Jun 16, 2017
·Updated
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.
Affected Software
2 affected componentsFixes available
rubygems/logstash-core<2.3.4
2.3.4
Elastic Logstash<=2.3.3
Event History
Jun 16, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 14, 2022
Advisory Published
12:58 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-1000221?
CVE-2016-1000221 is classified as a medium-severity vulnerability due to the potential exposure of sensitive information.
2
What types of information can be exposed by CVE-2016-1000221?
CVE-2016-1000221 can expose HTTP authorization headers that may contain sensitive credentials.
3
How do I fix CVE-2016-1000221?
To mitigate CVE-2016-1000221, upgrade Logstash to version 2.3.4 or later.
4
Which versions of Logstash are affected by CVE-2016-1000221?
CVE-2016-1000221 affects all versions of Logstash prior to 2.3.4.
5
What component of Logstash does CVE-2016-1000221 impact?
CVE-2016-1000221 specifically impacts the Elasticsearch Output plugin of Logstash.