PT-2025-19904 · Logstash · Logstash

·

CVE-2025-37730

·

Published

2025-05-06

·

Updated

2025-05-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Logstash (affected versions not specified)
Description The issue is related to improper certificate validation in Logstash's TCP output, which could lead to a man-in-the-middle (MitM) attack in "client" mode. This occurs because hostname verification in TCP output was not being performed when the ssl verification mode was set to full.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-LOGSTASH-2025-37730
CVE-2025-37730

Affected Products

Logstash