Описание
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.6.16 (исключая)Версия от 6.0.0 (включая) до 6.6.2 (исключая)
Одно из
cpe:2.3:a:elastic:winlogbeat:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:winlogbeat:*:*:*:*:*:*:*:*
EPSS
Процентиль: 40%
0.00179
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-778
NVD-CWE-Other
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.
EPSS
Процентиль: 40%
0.00179
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-778
NVD-CWE-Other