CVE-2019-7612 - CVE House
Back to Database
Status published Critical CVE-2019-7612

A sensitive data disclosure flaw was found in the way...

Vulnerability Description

A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-7612

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Logstash
Vulnerable Versions:
before 5.6.15 and 6.6.1

Timeline

Official Publish: March 25th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)