ADVISORIES
GEM
SEVERITY
CVSS v2.0: 7.5 (High)
UNAFFECTED VERSIONS
- < 1.0.14
PATCHED VERSIONS
- >= 1.4.2
DESCRIPTION
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows
remote attackers to execute arbitrary commands via a crafted
event in (1) zabbix.rb
or (2) nagios_nsca.rb
in outputs/
.
RELATED
- https://nvd.nist.gov/vuln/detail/CVE-2014-4326
- https://www.elastic.co/community/security
- https://web.archive.org/web/20140804031140/http://www.elasticsearch.org/blog/logstash-1-4-2
- https://web.archive.org/web/20201207013408/http://www.securityfocus.com/archive/1/532841/100/0/threaded
- https://github.com/advisories/GHSA-8qhq-rq4j-8prj