QID 379180

Date Published: 2024-01-15

QID 379180: Elasticsearch Logstash Insertion of Sensitive Information into Log File (ESA-2023-26)

ElasticSearch Logstash is an open source, server-side data processing pipeline that ingests data from a multitude of sources simultaneously, transforms it, and then sends it to your favorite 'stash'.

Affected Versions:
Elasticsearch Logstash version from 8.10.0 to 8.11.0.

QID Detection Logic (Authenticated):
This QID checks for vulnerable versions of Elasticsearch Logstash present on the target.

Successful exploitation of these vulnerabilities may affect confidentiality, integrity and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Update to version 8.11.1. Kibana can be downloaded at Download Kibana 8.11.1

    CVEs related to QID 379180

    Software Advisories
    Advisory ID Software Component Link
    ESA-2023-26 URL Logo discuss.elastic.co/t/logstash-8-11-1-security-update-esa-2023-26/347191