ZeroHour

CVE-2016-10362

CVSS 3.0
6.5 medium
EPSS
1%p63
Published
()
Modified
Description

Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

Vendors
elasticsearch
Products
output plugin
Weakness
CWE-532, CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.