Home/Product/elastic logstash
Product

elastic logstash

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-33466
>= 8.0.0 and < 8.19.14
Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially
8.1HIGH
CVE-2023-46672
>= 8.10.0 and < 8.11.1
An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The p
8.4HIGH
CVE-2021-22138
>= 6.4.0 and < 6.8.15
In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring featur
3.7LOW
CVE-2020-2143
<= 2.3.1
Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configurati
5.3MEDIUM
CVE-2019-7620
>= 6.0.0 and < 6.8.4
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated u
7.5HIGH
CVE-2019-7612
< 5.6.15
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malforme
9.8CRITICAL
CVE-2018-3817
< 5.6.6
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive
6.5MEDIUM
CVE-2017-14730
all versions
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-wri
7.8HIGH
CVE-2015-5619
all versions
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS cert
5.9MEDIUM
CVE-2015-5378
all versions
Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent
7.5HIGH
CVE-2016-10363
<= 2.3.2
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9
7.5HIGH
CVE-2016-1000222
<= 2.1.1
Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CS
7.5HIGH
CVE-2016-1000221
<= 2.3.3
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sens
7.5HIGH
CVE-2015-4152
<= 1.4.2
Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to writ
CVE-2014-4326
all versions
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin