{"id":"GHSA-vcmm-ppqx-95ch","summary":"Logstash Logs Sensitive Information","details":"Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.","aliases":["CVE-2016-1000221"],"modified":"2024-02-16T08:09:23.721451Z","published":"2022-05-14T00:58:12Z","database_specific":{"github_reviewed_at":"2023-07-28T20:52:56Z","nvd_published_at":"2017-06-16T21:29:00Z","cwe_ids":["CWE-200"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000221"},{"type":"WEB","url":"https://github.com/elastic/logstash/commit/0999050144adad7f4d99d43e561c2882fd7c512b"},{"type":"PACKAGE","url":"https://github.com/elastic/logstash"},{"type":"WEB","url":"https://web.archive.org/web/20210124065200/http://www.securityfocus.com/bid/99126"},{"type":"WEB","url":"https://www.elastic.co/community/security"}],"affected":[{"package":{"name":"logstash-core","ecosystem":"RubyGems","purl":"pkg:gem/logstash-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.4"}]}],"versions":["1.5.0","1.5.0.beta2","1.5.0.rc1","1.5.0.rc1.1","1.5.0.rc2","1.5.0.rc2.snapshot","1.5.0.rc3","1.5.0.rc3.snapshot1","1.5.0.rc3.snapshot2","1.5.0.rc3.snapshot3","1.5.0.rc3.snapshot4","1.5.0.rc3.snapshot5","1.5.0.rc3.snapshot6","1.5.0.rc4","1.5.0.rc4.snapshot1","1.5.0.rc4.snapshot2","1.5.0.snapshot1","1.5.1","1.5.1.snapshot1","1.5.2","1.5.2.1","1.5.2.2","1.5.2.snapshot1","1.5.2.snapshot2","1.5.3","1.5.3.snapshot1","1.5.3.snapshot2","1.5.4","1.5.4.snapshot1","1.5.4.snapshot2","1.5.4.snapshot3","1.5.5","1.5.6","2.0.0","2.0.0.beta1","2.0.0.beta2","2.0.0.beta3","2.0.0.rc1","2.0.1","2.0.1.snapshot1","2.1.0","2.1.0.snapshot1","2.1.0.snapshot2","2.1.0.snapshot3","2.1.0.snapshot4","2.1.1","2.1.2","2.1.2.snapshot1","2.1.3","2.2.0","2.2.0.snapshot2","2.2.0.snapshot3","2.2.1","2.2.1.snapshot1","2.2.2","2.2.3","2.2.3.snapshot2","2.2.4","2.2.4.snapshot1","2.2.4.snapshot2","2.3.0","2.3.0.snapshot1","2.3.0.snapshot3","2.3.0.snapshot4","2.3.0.snapshot5","2.3.1","2.3.1.snapshot1","2.3.2","2.3.2.snapshot1","2.3.3","2.3.3.snapshot1","2.3.3.snapshot2","2.3.4.snapshot1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vcmm-ppqx-95ch/GHSA-vcmm-ppqx-95ch.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}