CVE-2019-7612
25.03.2019, 19:29
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.Enginsight
Vendor | Product | Version |
---|---|---|
elastic | logstash | 𝑥 < 5.6.15 |
elastic | logstash | 6.0.0 ≤ 𝑥 < 6.6.1 |
netapp | active_iq_performance_analytics_services | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-209 - Generation of Error Message Containing Sensitive InformationThe software generates an error message that includes sensitive information about its environment, users, or associated data.
- CWE-532 - Insertion of Sensitive Information into Log FileInformation written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
References