elastic / elastic/logstash

Vulnerability found in logstash-oss:8.13.2

Open
#16,113 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
14.9k
Forks
3.5k
Avg merge
1d 4h
Merged PRs (30d)
88

Description

On scanning the logstash-oss:8.13.2 docker image, found the below vulnerability in it.

Type | Severity | CVSS | CVE | Package Name | Package Version | Fix Status
-- | -- | -- | -- | -- | -- | --
Jar | Critical | 9.8 | CVE-2022-46337 | derby | 10.15.2.1 | fixed in: 10.17.1.0
Jar | High | 7.1 | CVE-2023-2976 | com.google.guava_guava | 25.1-android | fixed in: 32.0.0
Product | Medium | 5.5 | CVE-2022-45146 | java | 17.0.10 | fixed in: 1.0.2.4
Jar | Moderate | 5.3 | CVE-2024-29025 | io.netty_netty-codec-http | 4.1.100.Final | fixed in: 4.1.108.Final
Jar | Medium | 4.7 | CVE-2023-35116 | com.fasterxml.jackson.core_jackson-databind | 2.15.2 | fixed in: 2.16.0
Jar | Medium | 4.7 | CVE-2023-35116 | com.fasterxml.jackson.core_jackson-databind | 2.15.3 | fixed in: 2.16.0
Package | Medium | 0 | CVE-2024-28834 | gnutls28 | 3.6.13-2ubuntu1.10 | fixed in: 3.6.13-2ubuntu1.11
Jar | Low | 3.7 | CVE-2020-9488 | org.apache.logging.log4j_log4j | 1.2-api-2 | fixed in: 2.3.2, 2.12.3, 2.13.2
Jar | Low | 3.3 | CVE-2020-8908 | com.google.guava_guava | 25.1-android | fixed in: 32.0.0

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the scan against the logstash-oss:8.13.2 Docker image and review the reported Java and system packages, including derby, Guava, Netty, Jackson, Log4j, gnutls28, and Java. Done means the affected components are updated to versions addressing the listed CVEs and a follow-up scan no longer reports them.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, java
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.