Show filters
61 Total Results
Displaying 31-40 of 61
Sort by:
Attacker Value
Unknown

CVE-2020-5626

Disclosure Date: January 28, 2021 (last updated February 22, 2025)
Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbitrary OS commands via a specially crafted log file.
Attacker Value
Unknown

CVE-2020-2143

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
Attacker Value
Unknown

CVE-2019-7620

Disclosure Date: October 30, 2019 (last updated November 27, 2024)
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop responding.
Attacker Value
Unknown

CVE-2019-14521

Disclosure Date: August 05, 2019 (last updated November 27, 2024)
The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter.
0
Attacker Value
Unknown

CVE-2019-1003062

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
Jenkins AWS CloudWatch Logs Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Attacker Value
Unknown

CVE-2019-7612

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL could be inadvertently logged as part of the error message.
Attacker Value
Unknown

CVE-2019-6979

Disclosure Date: January 28, 2019 (last updated November 27, 2024)
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_logs.php useragent field.
0
Attacker Value
Unknown

CVE-2018-3824

Disclosure Date: September 19, 2018 (last updated November 27, 2024)
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of that other ML user.
0
Attacker Value
Unknown

CVE-2018-3823

Disclosure Date: September 19, 2018 (last updated November 27, 2024)
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of other ML users viewing the results of the jobs.
Attacker Value
Unknown

CVE-2018-3817

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
0