Vulnerability CVE-2023-46672


Published: 2023-11-15

Description:
An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances.

The prerequisites for the manifestation of this issue are:

* Logstash is configured to log in JSON format https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html , which is not the default logging format.


* Sensitive data is stored in the Logstash keystore and referenced as a variable in Logstash configuration.






 References:
https://discuss.elastic.co/t/logstash-8-11-1-security-update-esa-2023-26/347191
https://www.elastic.co/community/security

Copyright 2026, cxsecurity.com

 

Back to Top