CVE-2016-1000222: Elastic Logstash

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.

Affected products

  • Elastic Logstash: up to and including 2.1.1

Published 2017-06-16. Last modified 2026-06-17.