Remote Command Execution in Elasticsearch Logstash by Elasticsearch
CVE-2014-4326

Currently unrated

Key Information:

Vendor
Elastic
Status
Vendor
CVE Published:
22 July 2014

Summary

Elasticsearch Logstash versions 1.0.14 through 1.4.x prior to 1.4.2 expose a serious vulnerability allowing remote attackers to execute arbitrary commands on the server. This can be achieved by sending specially crafted events through the 'zabbix.rb' or 'nagios_nsca.rb' output plugins. The affected versions lack proper validation and sanitization of input data, which opens the door to exploitation. It's crucial for users to update to the latest version to safeguard their systems against potential attacks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.