Skip to main content

Vendor/product archive

elastic / logstash CVEs

Beta · best-effort

13 CVEs tagged to elastic / logstash1 Critical, 8 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2026-33466

Published Apr 8, 2026

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-46672

Published Nov 15, 2023

An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for the manifestation of this issue…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22138

Published May 13, 2021

In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When specifying a trusted server CA certificat…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-7620

Published Oct 30, 2019

Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logsta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3817

Published Mar 30, 2018

When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5619

Published Aug 9, 2017

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might al…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10363

Published Jun 16, 2017

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of servi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000222

Published Jun 16, 2017

Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000221

Published Jun 16, 2017

Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4152

Published Jun 15, 2015

Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary files via vectors related to dynam…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4326

Published Jul 22, 2014

Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in output…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1