VYPR
Low severity3.7NVD Advisory· Published May 13, 2021· Updated Jun 17, 2026

CVE-2021-22138

CVE-2021-22138

Description

In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When specifying a trusted server CA certificate Logstash would not properly verify the certificate returned by the monitoring server. This could result in a man in the middle style attack against the Logstash monitoring data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Elastic/Logstash2 versions
    cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:*range: >=6.4.0,<6.8.15
    • (no CPE)range: >=6.4.0,<6.8.15 and <7.12.0
  • osv-coords
    Range: >= 6.4.0, < 6.8.15
  • Range: after 6.4.0 and before 6.8.15 and 7.12.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.