When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
The product writes sensitive information to a log file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://discuss.elastic.co/t/elastic-stack-6-1-2-and-5-6-6-security-update/115763 | vendor advisory |