Skip to content

Commit c6ae4cb

Browse files
jasnowRubySec CI
authored and
RubySec CI
committed
Updated advisory posts against rubysec/ruby-advisory-db@6140107
1 parent c9d005e commit c6ae4cb

File tree

1 file changed

+31
-0
lines changed

1 file changed

+31
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2014-4326 (logstash): Elasticsearch Logstash allows remote attackers to
4+
execute arbitrary commands'
5+
comments: false
6+
categories:
7+
- logstash
8+
advisory:
9+
gem: logstash
10+
cve: 2014-4326
11+
ghsa: 8qhq-rq4j-8prj
12+
url: https://www.elastic.co/community/security
13+
title: Elasticsearch Logstash allows remote attackers to execute arbitrary commands
14+
date: 2022-05-14
15+
description: |
16+
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows
17+
remote attackers to execute arbitrary commands via a crafted
18+
event in (1) `zabbix.rb` or (2) `nagios_nsca.rb` in `outputs/`.
19+
cvss_v2: 7.5
20+
unaffected_versions:
21+
- "< 1.0.14"
22+
patched_versions:
23+
- ">= 1.4.2"
24+
related:
25+
url:
26+
- https://nvd.nist.gov/vuln/detail/CVE-2014-4326
27+
- https://www.elastic.co/community/security
28+
- https://web.archive.org/web/20140804031140/http://www.elasticsearch.org/blog/logstash-1-4-2
29+
- https://web.archive.org/web/20201207013408/http://www.securityfocus.com/archive/1/532841/100/0/threaded
30+
- https://github.com/advisories/GHSA-8qhq-rq4j-8prj
31+
---

0 commit comments

Comments
 (0)