CVE-2017-11480: Elasticsearch Packetbeat
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.
Affected products
- Elasticsearch Packetbeat: before 5.6.4 (fixed in 5.6.4)
Published 2017-12-08. Last modified 2026-06-17.