CVE-2019-7612: Elastic Logstash
Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.
Affected products
- Elastic Logstash: before 5.6.15 (fixed in 5.6.15); from 6.0.0, before 6.6.1 (fixed in 6.6.1)
- Netapp Active Iq Performance Analytics Services: affected versions not specified
Published 2019-03-25. Last modified 2026-06-17.