HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2019-7613

CVSS 7.5v3.1pub. 2019-03-25upd. 2024-11-21

Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • Elastic Winlogbeat

    APP
    Elastic
    < 5.6.166.0.0 – 6.6.2 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same vendor

RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu

CVE-2015-1427CRITICAL9.8⚠ KEVPL ✓same vendor

Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń

CVE-2025-37729CRITICAL9.1PL ✓same vendor

Elastic Cloud Enterprise — Server-Side Template Injection (SSTI) w silniku Jinjava

CVE-2025-25014CRITICAL9.1PL ✓same vendor

Prototype Pollution w Kibana prowadzące do RCE przez HTTP

CVE-2025-25015CRITICAL9.9PL ✓same vendor

Prototype Pollution w Elastic Kibana umożliwia zdalne wykonanie kodu (RCE)