Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6fg-prgw-3ff5

Опубликовано: 15 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances.

The prerequisites for the manifestation of this issue are:

An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances.

The prerequisites for the manifestation of this issue are:

EPSS

Процентиль: 35%
0.00147
Низкий

8.4 High

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 8.4
nvd
около 2 лет назад

An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for the manifestation of this issue are: * Logstash is configured to log in JSON format https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html , which is not the default logging format. * Sensitive data is stored in the Logstash keystore and referenced as a variable in Logstash configuration.

CVSS3: 8.4
debian
около 2 лет назад

An issue was identified by Elastic whereby sensitive information is re ...

CVSS3: 8.4
fstec
около 2 лет назад

Уязвимость конвейера обработки данных на стороне сервера Elastic Logstash, связанная с раскрытием информации через регистрационные файлы, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 35%
0.00147
Низкий

8.4 High

CVSS3

Дефекты

CWE-532