Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled.
2023-05-04T21:15:11.640
2025-01-29T19:15:16.867
Modified
CVSSv3.1: 3.3 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | elastic | filebeat | ≤ 7.17.9 | Yes |
Application | elastic | filebeat | 8.6.2 | Yes |