ZeroHour

CVE-2019-7612

CVSS 3.1
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.

Vendors
elasticnetapp
Products
logstash, active iq performance analytics services
Weakness
CWE-209, CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.