VYPR

by Elasticsearch

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-14730Hig0.517.80.00Sep 25, 2017The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.
CVE-2015-5378Hig0.497.50.01Jun 27, 2017Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.