CVE Vulnerabilities

CVE-2015-5619

Improper Certificate Validation

Published: Aug 09, 2017 | Modified: Jun 17, 2019
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Logstash Elastic 1.4.0 (including) 1.4.0 (including)
Logstash Elastic 1.4.1 (including) 1.4.1 (including)
Logstash Elastic 1.4.2 (including) 1.4.2 (including)
Logstash Elasticsearch 1.4.3 (including) 1.4.3 (including)
Logstash Elasticsearch 1.4.4 (including) 1.4.4 (including)
Logstash Elasticsearch 1.5.0 (including) 1.5.0 (including)
Logstash Elasticsearch 1.5.1 (including) 1.5.1 (including)
Logstash Elasticsearch 1.5.2 (including) 1.5.2 (including)
Logstash Elasticsearch 1.5.3 (including) 1.5.3 (including)

Potential Mitigations

References