CVE-2019-7612

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
25/03/2019
Last modified:
05/10/2020

Description

A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:* 5.6.15 (excluding)
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:* 6.0.0 (including) 6.6.1 (excluding)
cpe:2.3:a:netapp:active_iq_performance_analytics_services:-:*:*:*:*:*:*:*