The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.
2017-09-25T17:29:00.787
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | elasticsearch | logstash | 5.0.0 | Yes |
Application | elasticsearch | logstash | 5.0.1 | Yes |
Application | elasticsearch | logstash | 5.0.2 | Yes |
Application | elasticsearch | logstash | 5.1.1 | Yes |
Application | elasticsearch | logstash | 5.1.2 | Yes |
Application | elasticsearch | logstash | 5.2.0 | Yes |
Application | elasticsearch | logstash | 5.2.1 | Yes |
Application | elasticsearch | logstash | 5.3.0 | Yes |
Application | elasticsearch | logstash | 5.3.1 | Yes |
Application | elasticsearch | logstash | 5.3.2 | Yes |
Application | elasticsearch | logstash | 5.4.1 | Yes |
Application | elasticsearch | logstash | 5.4.2 | Yes |
Application | elasticsearch | logstash | 5.4.3 | Yes |
Application | elasticsearch | logstash | 5.5.0 | Yes |
Application | elasticsearch | logstash | 5.5.1 | Yes |
Application | elasticsearch | logstash | 5.5.2 | Yes |
Application | elasticsearch | logstash | 5.6.0 | Yes |
Operating System | gentoo | linux | - | No |