Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Logstash | Elastic | 1.4.0 (including) | 1.4.0 (including) |
Logstash | Elastic | 1.4.1 (including) | 1.4.1 (including) |
Logstash | Elastic | 1.4.2 (including) | 1.4.2 (including) |
Logstash | Elasticsearch | 1.4.3 (including) | 1.4.3 (including) |
Logstash | Elasticsearch | 1.4.4 (including) | 1.4.4 (including) |
Logstash | Elasticsearch | 1.5.0 (including) | 1.5.0 (including) |
Logstash | Elasticsearch | 1.5.1 (including) | 1.5.1 (including) |
Logstash | Elasticsearch | 1.5.2 (including) | 1.5.2 (including) |
Logstash | Elasticsearch | 1.5.3 (including) | 1.5.3 (including) |