First published: Wed Oct 30 2019(Updated: )
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop responding.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Logstash | >=6.0.0<6.8.4 | |
Elastic Logstash | >=7.0.0<7.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7620 is a denial of service vulnerability in Logstash versions before 7.4.1 and 6.8.4.
CVE-2019-7620 allows an unauthenticated user to send a specially crafted network packet that could cause Logstash to stop responding.
CVE-2019-7620 has a severity rating of 7.5 (high).
To fix CVE-2019-7620, update Logstash to version 7.4.1 or 6.8.4.
You can find more information about CVE-2019-7620 in the Elastic community security page.