CVE-2016-10362: Infoleak
Published Jun 16, 2017
·Updated
Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
Affected Software
2 affected componentsFixes available
rubygems/logstash-core<5.0.1
5.0.1
Elasticsearch Output Plugin Logstash<=5.0.0
Event History
Jun 16, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
May 13, 2022
Advisory Published
01:38 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-10362?
CVE-2016-10362 is categorized as a moderate severity vulnerability due to the exposure of sensitive HTTP basic auth credentials.
2
How do I fix CVE-2016-10362?
To fix CVE-2016-10362, upgrade Logstash to version 5.0.1 or later.
3
What type of credentials are exposed in CVE-2016-10362?
CVE-2016-10362 exposes HTTP basic authentication credentials to log files when updating connections.
4
Which versions of Logstash are affected by CVE-2016-10362?
CVE-2016-10362 affects all versions prior to Logstash 5.0.1.
5
What is the impact of CVE-2016-10362 on Elasticsearch Output plugin users?
The impact of CVE-2016-10362 includes potential leakage of sensitive authentication information through log files.