Medium severity5.9NVD Advisory· Published Aug 9, 2017· Updated May 13, 2026
CVE-2015-5619
CVE-2015-5619
Description
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.com/files/133269/Logstash-1.5.3-Man-In-The-Middle.htmlnvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/76455nvdThird Party AdvisoryVDB Entry
- www.elastic.co/blog/logstash-1-5-4-and-1-4-5-releasednvdVendor Advisory
- www.securityfocus.com/archive/1/536294/100/0/threadednvd
- www.securityfocus.com/archive/1/536858/100/0/threadednvd
News mentions
0No linked articles in our index yet.