CVE-2016-10362: Elasticsearch Output Plugin
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
Affected products
- Elasticsearch Output Plugin: up to and including 5.0.0
Published 2017-06-16. Last modified 2026-06-17.