A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077 | vendor advisory |
https://www.elastic.co/community/security | vendor advisory |
https://security.netapp.com/advisory/ntap-20190411-0002/ | third party advisory |