Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-5619

Опубликовано: 09 авг. 2017
Источник: debian
EPSS Низкий

Описание

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
logstashitppackage

EPSS

Процентиль: 53%
0.00306
Низкий

Связанные уязвимости

CVSS3: 5.9
nvd
больше 8 лет назад

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

CVSS3: 5.9
github
больше 3 лет назад

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

EPSS

Процентиль: 53%
0.00306
Низкий