Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.
References
| Link | Resource |
|---|---|
| https://www.elastic.co/community/security | Vendor Advisory |
| https://www.elastic.co/community/security | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2017-06-16 21:29
Updated : 2025-04-20 01:37
NVD link : CVE-2016-10363
Mitre link : CVE-2016-10363
CVE.ORG link : CVE-2016-10363
JSON object : View
Products Affected
elastic
- logstash
