Elastic Logstash
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*
- >= 8, < 8.19.14
- >= 9, < 9.2.8
- >= 9, < 9.3.3
A vulnerability in Logstash exists due to improper validation of file paths in the archive extraction utilities. This flaw allows for relative path traversal, leading to arbitrary file writes on the host filesystem with the privileges of the Logstash process. If a specially crafted archive is served to Logstash through a compromised update endpoint, the vulnerability can be exploited. In configurations with automatic pipeline reloading enabled, this could escalate to remote code execution.
Exploitation of this vulnerability could result in arbitrary file writes and potentially allow for remote code execution, especially in configurations with automatic pipeline reloading enabled.
Users can update to Logstash versions 8.19.14, 9.2.8, or 9.3.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.