Elastic / Logstash
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-33466 | Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write | CRITICAL | 9.8 | Apr 8, 2026 |
| CVE-2025-37730 | Logstash Improper Certificate Validation in TCP output | MEDIUM | 6.5 | May 6, 2025 |
| CVE-2023-46672 | Logstash Insertion of Sensitive Information into Log File | HIGH | 8.4 | Nov 15, 2023 |
| CVE-2021-22138 | In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When specifying a trusted… | LOW | 3.7 | May 13, 2021 |
| CVE-2019-7620 | Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to… | HIGH | 7.5 | Oct 30, 2019 |
| CVE-2019-7613 | Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winl… | HIGH | 7.5 | Mar 25, 2019 |
| CVE-2019-7612 | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of… | CRITICAL | 9.8 | Mar 25, 2019 |
| CVE-2018-3817 | When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information. | MEDIUM | 6.5 | Mar 30, 2018 |
| CVE-2015-5619 | Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash se… | MEDIUM | 5.9 | Aug 9, 2017 |
| CVE-2015-5378 | Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server. | HIGH | 7.5 | Jun 27, 2017 |
| CVE-2016-10363 | Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perfo… | HIGH | 7.5 | Jun 16, 2017 |
| CVE-2016-10362 | Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials. | MEDIUM | 6.5 | Jun 16, 2017 |
| CVE-2016-1000222 | Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data. | HIGH | 7.5 | Jun 16, 2017 |
| CVE-2016-1000221 | Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information. | HIGH | 7.5 | Jun 16, 2017 |
| CVE-2015-4152 | Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary files via vect… | MEDIUM | 6.4 | Jun 15, 2015 |
| CVE-2014-4326 | Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagi… | HIGH | 8.1 | Jul 22, 2014 |
Showing 1 to 13 of 13 CVEs