Company
Date Published
Author
Pier-Hugues Pellerin
Word count
472
Language
-
Hacker News points
None

Summary

Logstash versions 1.5.4 and 1.4.5 have been released, addressing important security vulnerabilities and adding enhancements. The update primarily fixes an SSL/TLS certificate validation issue in Logstash Forwarder and a man-in-the-middle vulnerability in Lumberjack output, assigned CVE-2015-5619. Enhancements include the addition of new Elasticsearch output features, allowing document updates and upserts if documents do not exist, thanks to contributions from David Chauviere. Bug fixes include improvements to SSL handling, suppression of deprecation warnings, and better management of congestion scenarios in Lumberjack output. Users are encouraged to upgrade immediately and provide feedback through social media or GitHub.