CVE-2019-7612

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/03/2019
Last modified:
17/06/2026

Description

A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:* 5.6.15 (excluding)
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:* 6.0.0 (including) 6.6.1 (excluding)
cpe:2.3:a:netapp:active_iq_performance_analytics_services:-:*:*:*:*:*:*:*