CVE Vulnerabilities

CVE-2023-46672

Insertion of Sensitive Information into Log File

Published: Nov 15, 2023 | Modified: Feb 13, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances.

The prerequisites for the manifestation of this issue are:

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
LogstashElastic8.10.0 (including)8.11.1 (excluding)
LogstashElastic7.12.1 (including)7.12.1 (including)

Potential Mitigations

References