CVE-2015-5619
medium
CVSS v3
5.9
CVSS v2
4.3
VIR risk
5.9
Description
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.
Predictions
Exploit likelihood
69%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://www.elastic.co/blog/logstash-1-5-4-and-1-4-5-released
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| RubyGems | logstash-core | <~> 1.4.5 | ~> 1.4.5 |
References
- https://www.elastic.co/blog/logstash-1-5-4-and-1-4-5-released
- http://packetstormsecurity.com/files/133269/Logstash-1.5.3-Man-In-The-Middle.html
- http://www.securityfocus.com/archive/1/536294/100/0/threaded
- http://www.securityfocus.com/archive/1/536858/100/0/threaded
- http://www.securityfocus.com/bid/76455
CWEs
CWE-295
Verify integrity in audit chain (admin only). AS-IS.