Arbitrary File Write Vulnerability in Elasticsearch Logstash

Arbitrary File Write Vulnerability in Elasticsearch Logstash

CVE-2015-4152 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:P

Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary files via vectors related to dynamic field references in the path option.

Learn more about our Web Application Penetration Testing UK.