RubySec

Providing security resources for the Ruby community

CVE-2014-4326 (logstash): Elasticsearch Logstash allows remote attackers to execute arbitrary commands

ADVISORIES

GEM

logstash

SEVERITY

CVSS v2.0: 7.5 (High)

UNAFFECTED VERSIONS

  • < 1.0.14

PATCHED VERSIONS

  • >= 1.4.2

DESCRIPTION

Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.

RELATED