CVE-2023-46672
Logstash Insertion of Sensitive Information into Log File
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for the manifestation of this issue are: * Logstash is configured to log in JSON format https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html , which is not the default logging format. * Sensitive data is stored in the Logstash keystore and referenced as a variable in Logstash configuration.
Elastic identificó un problema por el cual se registra información confidencial en los registros de Logstash en circunstancias específicas. Los requisitos previos para la manifestación de este problema son: * Logstash está configurado para iniciar sesión en formato JSON https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html, que no es el formato de registro predeterminado. * Los datos confidenciales se almacenan en el almacén de claves de Logstash y se hace referencia a ellos como una variable en la configuración de Logstash.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-10-24 CVE Reserved
- 2023-11-15 CVE Published
- 2024-01-31 EPSS Updated
- 2025-02-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (4)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.elastic.co/community/security | 2024-03-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Elastic Search vendor "Elastic" | Logstash Search vendor "Elastic" for product "Logstash" | >= 8.10.0 < 8.11.1 Search vendor "Elastic" for product "Logstash" and version " >= 8.10.0 < 8.11.1" | - |
Affected
| ||||||
Elastic Search vendor "Elastic" | Logstash Search vendor "Elastic" for product "Logstash" | 7.12.1 Search vendor "Elastic" for product "Logstash" and version "7.12.1" | - |
Affected
|