Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Logstash Improper Certificate Validation in TCP output
Vulnerability Description
Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not being performed when the ssl_verification_mode => full was set.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
证书验证不恰当
Vulnerability Title
Elastic Logstash 安全漏洞
Vulnerability Description
Elastic Logstash是荷兰Elastic公司的一套日志分析和监控工具。 Elastic Logstash 9.0.1之前版本存在安全漏洞,该漏洞源于证书验证不当,可能导致中间人攻击。
CVSS Information
N/A
Vulnerability Type
N/A