CVE-2019-7620: High severity logstash management api vulnerability
Published Oct 30, 2019
·Updated
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop responding.
Affected Software
2 affected components
Elastic Logstash>=6.0.0<6.8.4
Elastic Logstash>=7.0.0<7.4.1
Event History
Oct 30, 2019
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-7620?
CVE-2019-7620 is a denial of service vulnerability in Logstash versions before 7.4.1 and 6.8.4.
2
How does CVE-2019-7620 impact Logstash?
CVE-2019-7620 allows an unauthenticated user to send a specially crafted network packet that could cause Logstash to stop responding.
3
What is the severity of CVE-2019-7620?
CVE-2019-7620 has a severity rating of 7.5 (high).
4
How can I fix CVE-2019-7620?
To fix CVE-2019-7620, update Logstash to version 7.4.1 or 6.8.4.
5
Where can I find more information about CVE-2019-7620?
You can find more information about CVE-2019-7620 in the Elastic community security page.