7.8
CVSSv3

CVE-2017-14730

Published: 25/09/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The init script in the Gentoo app-admin/logstash-bin package prior to 5.5.3 and 5.6.x prior to 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elasticsearch logstash 5.0.2

elasticsearch logstash 5.1.2

elasticsearch logstash 5.4.2

elasticsearch logstash 5.5.0

elasticsearch logstash 5.2.1

elasticsearch logstash 5.3.0

elasticsearch logstash 5.3.1

elasticsearch logstash 5.3.2

elasticsearch logstash 5.5.1

elasticsearch logstash 5.5.2

elasticsearch logstash 5.6.0

elasticsearch logstash 5.0.0

elasticsearch logstash 5.0.1

elasticsearch logstash 5.1.1

elasticsearch logstash 5.2.0

elasticsearch logstash 5.4.1

elasticsearch logstash 5.4.3