CVE-2019-7612: Critical severity logstash management api vulnerability
Published Mar 25, 2019
·Updated
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.
Affected Software
3 affected components
Elastic Logstash<5.6.15
Elastic Logstash>=6.0.0<6.6.1
NetApp Active Iq Performance Analytics Services
Event History
Mar 25, 2019
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Logstash flaw?
The vulnerability ID for this Logstash flaw is CVE-2019-7612.
2
What is the severity of CVE-2019-7612?
The severity of CVE-2019-7612 is critical with a CVSS score of 9.8.
3
Which versions of Logstash are affected by CVE-2019-7612?
Logstash versions before 5.6.15 and 6.6.1 are affected by CVE-2019-7612.
4
What is the impact of CVE-2019-7612?
CVE-2019-7612 can result in the disclosure of sensitive data if a malformed URL is specified in the Logstash configuration.
5
How can I fix CVE-2019-7612?
To fix CVE-2019-7612, upgrade to Logstash version 5.6.15 or 6.6.1.