CVE-2015-5378: Elastic Logstash
High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.
Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.
Affected products
- Elastic Logstash: version 1.4.0 only; version 1.4.1 only; version 1.4.2 only
- Elasticsearch Logstash: version 1.4.3 only; version 1.5.0 only; version 1.5.1 only; version 1.5.2 only
Published 2017-06-27. Last modified 2026-06-17.