First published: Fri Mar 30 2018(Updated: )
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Logstash | <5.6.6 | |
Elastic Logstash | >=6.0.0<6.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Logstash vulnerability is CVE-2018-3817.
The severity of CVE-2018-3817 is medium with a severity value of 6.5.
Logstash versions before 5.6.6 and 6.x before 6.1.2 are affected by CVE-2018-3817.
CVE-2018-3817 refers to a vulnerability in Logstash that could inadvertently log sensitive information when logging warnings about deprecated settings.
Yes, upgrading to Logstash version 5.6.6 or 6.x version 6.1.2 or newer will fix the vulnerability.