CVE-2016-10362

Description

Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.28

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-10362 are fixed in Ruby-logstash-core 5.0.1Windows
Vulnerabilities CVE-2016-10362 are fixed in Ruby-logstash-core for Linux 5.0.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234