Logstash 1.5.3 Man-In-The-Middle

Discussion in 'News Aggregator' started by Packet Storm, 24 Aug 2015.

  1. Packet Storm

    Packet Storm Guest

    Logstash 1.5.3 and prior versions are vulnerable to a SSL/TLS security issue which allows an attacker to successfully implement a man in the middle attack. This vulnerability is not present in the initial installation of Logstash. This insecurity is exposed when users configure Lumberjack output to connect two Logstash instances. In such deployments, a Logstash instance is used to collect logs from a webserver and securely transmit them to a central Logstash instance to perform additional filtering and storing.

    Continue reading...
     

Share This Page

Loading...