Skip to main content

Vendor/product archive

elasticsearch / logstash CVEs

Beta · best-effort

3 CVEs tagged to elasticsearch / logstash0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2017-14730

Published Sep 25, 2017

The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5619

Published Aug 9, 2017

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might al…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1