Back to search
CVE-2015-5619
Published: Aug 9, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
76455
vdb-entry
x_refsource_BID
https://www.elastic.co/blog/logstash-1-5-4-and-1-4-5-released
x_refsource_CONFIRM
20150821 Logstash vulnerability CVE-2015-5619
mailing-list
x_refsource_BUGTRAQ
20151106 CVE-2015-5619
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now