FS#70138 - [logstash] [Security] certificate verification bypass (CVE-2021-22138)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Tuesday, 23 March 2021, 18:51 GMT
Last edited by T.J. Townsend (blakkheim) - Saturday, 29 October 2022, 20:27 GMT
Opened by Jonas Witschel (diabonas) - Tuesday, 23 March 2021, 18:51 GMT
Last edited by T.J. Townsend (blakkheim) - Saturday, 29 October 2022, 20:27 GMT
|
Details
Summary
======= The package logstash is vulnerable to certificate verification bypass via CVE-2021-22138. Guidance ======== Upgrading Logstash to version 7.12.0 fixes the issue. References ========== https://security.archlinux.org/AVG-1730 https://discuss.elastic.co/t/elastic-stack-7-12-0-and-6-8-15-security-update/268125 |
This task depends upon
Closed by T.J. Townsend (blakkheim)
Saturday, 29 October 2022, 20:27 GMT
Reason for closing: Won't fix
Additional comments about closing: logstash was dropped to the AUR some time ago.
Saturday, 29 October 2022, 20:27 GMT
Reason for closing: Won't fix
Additional comments about closing: logstash was dropped to the AUR some time ago.