Vulnerability Description
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Winlogbeat | < 5.6.16 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/elastic-stack-6-6-2-and-5-6-16-security-update/1731Vendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
- https://discuss.elastic.co/t/elastic-stack-6-6-2-and-5-6-16-security-update/1731Vendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
FAQ
What is CVE-2019-7613?
CVE-2019-7613 is a vulnerability with a CVSS score of 7.5 (HIGH). Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.
How severe is CVE-2019-7613?
CVE-2019-7613 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-7613?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Winlogbeat.