Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x36p-26r2-96m6

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.

EPSS

Процентиль: 69%
0.00598
Низкий

7.5 High

CVSS3

Дефекты

CWE-248
CWE-404

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.

CVSS3: 7.5
debian
больше 8 лет назад

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, ...

EPSS

Процентиль: 69%
0.00598
Низкий

7.5 High

CVSS3

Дефекты

CWE-248
CWE-404