CVE-2025-37730
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
06/05/2025
Last modified:
07/05/2025
Description
Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not being performed when the ssl_verification_mode => full was set.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



