Home / Companies / Elastic / Blog / Post Details
Content Deep Dive

Logstash 2.2.2 released with important security bug fix

Blog post from Elastic

Post Details
Company
Date Published
Author
Suyog Rao
Word Count
152
Company Posts That Month
22
Language
-
Hacker News Points
-
Post removed?
No
Summary

Logstash version 2.2.2 has been released with a crucial security bug fix addressing a vulnerability present in version 2.2.1, which made it susceptible to a man-in-the-middle attack when used with Elasticsearch output due to the inadvertent disabling of SSL/TLS configuration by default. This vulnerability allowed unauthorized access to payload data transmitted via HTTP during the initial handshake. Users are encouraged to upgrade to version 2.2.2 to resolve this issue, but those unable to upgrade immediately can mitigate the risk by using the "https" prefix in their host configuration and then restarting Logstash.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.