CVE-2017-14730: High severity logstash management api vulnerability
Published Sep 25, 2017
·Updated
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LSUSER account for creation of a hard link.
Affected Software
18 affected components
Elasticsearch Logstash=5.0.0
Elasticsearch Logstash=5.0.1
Elasticsearch Logstash=5.0.2
Elasticsearch Logstash=5.1.1
Elasticsearch Logstash=5.1.2
Elasticsearch Logstash=5.2.0
Elasticsearch Logstash=5.2.1
Elasticsearch Logstash=5.3.0
Elasticsearch Logstash=5.3.1
Elasticsearch Logstash=5.3.2
Elasticsearch Logstash=5.4.1
Elasticsearch Logstash=5.4.2
Elasticsearch Logstash=5.4.3
Elasticsearch Logstash=5.5.0
Elasticsearch Logstash=5.5.1
Elasticsearch Logstash=5.5.2
Elasticsearch Logstash=5.6.0
Gentoo Linux
Event History
Sep 25, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14730?
CVE-2017-14730 has a medium severity rating as it allows local users to gain elevated privileges.
2
How do I fix CVE-2017-14730?
To fix CVE-2017-14730, update the Gentoo app-admin/logstash-bin package to version 5.5.3 or later.
3
What versions are affected by CVE-2017-14730?
CVE-2017-14730 affects logstash versions prior to 5.5.3 and 5.6.x before 5.6.1.
4
Who is affected by CVE-2017-14730?
Local users with access to a $LS_USER account are potentially affected by CVE-2017-14730.
5
What type of vulnerability is CVE-2017-14730?
CVE-2017-14730 is a privilege escalation vulnerability due to insecure handling of user-writable directory permissions.