CVE-2018-3817: Infoleak
Published Mar 30, 2018
·Updated
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
Affected Software
2 affected components
Elastic Logstash<5.6.6
Elastic Logstash>=6.0.0<6.1.2
Event History
Mar 30, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Logstash vulnerability?
The vulnerability ID for this Logstash vulnerability is CVE-2018-3817.
2
What is the severity of CVE-2018-3817?
The severity of CVE-2018-3817 is medium with a severity value of 6.5.
3
What is affected by CVE-2018-3817?
Logstash versions before 5.6.6 and 6.x before 6.1.2 are affected by CVE-2018-3817.
4
What is the description of CVE-2018-3817?
CVE-2018-3817 refers to a vulnerability in Logstash that could inadvertently log sensitive information when logging warnings about deprecated settings.
5
Is there a fix for CVE-2018-3817?
Yes, upgrading to Logstash version 5.6.6 or 6.x version 6.1.2 or newer will fix the vulnerability.