Skip to content

[GHSA-8qhq-rq4j-8prj] Elasticsearch Logstash allows remote attackers to execute arbitrary commands#5470

Closed
rtmcmill2009 wants to merge 1 commit intortmcmill2009/advisory-improvement-5470from
rtmcmill2009-GHSA-8qhq-rq4j-8prj
Closed

[GHSA-8qhq-rq4j-8prj] Elasticsearch Logstash allows remote attackers to execute arbitrary commands#5470
rtmcmill2009 wants to merge 1 commit intortmcmill2009/advisory-improvement-5470from
rtmcmill2009-GHSA-8qhq-rq4j-8prj

Conversation

@rtmcmill2009
Copy link
Copy Markdown

Updates

  • CVSS v3
  • CVSS v4
  • Severity

Comments
Request removal of this CVE as Ruby Advisory github shows that this CVE is exposed in logstash and not logstash-event: rubysec/ruby-advisory-db#867. Request for removal.

@github-actions github-actions bot changed the base branch from main to rtmcmill2009/advisory-improvement-5470 April 17, 2025 14:11
@JonathanLEvans
Copy link
Copy Markdown

Hi @rtmcmill2009, logstash-event has already been removed from the advisory. Are you saying that logstash is also not affected?

@rtmcmill2009
Copy link
Copy Markdown
Author

rtmcmill2009 commented Apr 17, 2025

Hi Jonathan, I misread the advisory. I see this references logstash and not logstash-event

@github-actions github-actions bot deleted the rtmcmill2009-GHSA-8qhq-rq4j-8prj branch April 17, 2025 15:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants