Vulnerability Description
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Logstash | 1.4.0 |
| Elasticsearch | Logstash | 1.4.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/133269/Logstash-1.5.3-Man-In-The-Middle.htmThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/536294/100/0/threaded
- http://www.securityfocus.com/archive/1/536858/100/0/threaded
- http://www.securityfocus.com/bid/76455Third Party AdvisoryVDB Entry
- https://www.elastic.co/blog/logstash-1-5-4-and-1-4-5-releasedVendor Advisory
- http://packetstormsecurity.com/files/133269/Logstash-1.5.3-Man-In-The-Middle.htmThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/536294/100/0/threaded
- http://www.securityfocus.com/archive/1/536858/100/0/threaded
- http://www.securityfocus.com/bid/76455Third Party AdvisoryVDB Entry
- https://www.elastic.co/blog/logstash-1-5-4-and-1-4-5-releasedVendor Advisory
FAQ
What is CVE-2015-5619?
CVE-2015-5619 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obta...
How severe is CVE-2015-5619?
CVE-2015-5619 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5619?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Logstash, Elasticsearch Logstash.