Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
The product writes sensitive information to a log file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.elastic.co/community/security | vendor advisory |
http://www.securityfocus.com/bid/99154 | third party advisory vdb entry |