{"id":"CVE-2014-4326","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-4326","summary":"Elasticsearch Logstash allows remote attackers to execute arbitrary commands","details":"Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) `zabbix.rb` or (2) `nagios_nsca.rb` in `outputs/`.","published":"2022-05-14T00:58:13Z","modified":"2025-04-16T17:18:13Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"logstash","fixedVersion":"1.4.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-4326"},{"type":"PACKAGE","url":"https://github.com/elastic/logstash"},{"type":"WEB","url":"https://web.archive.org/web/20140804031140/http://www.elasticsearch.org/blog/logstash-1-4-2"},{"type":"WEB","url":"https://web.archive.org/web/20201207013408/http://www.securityfocus.com/archive/1/532841/100/0/threaded"},{"type":"WEB","url":"https://www.elastic.co/community/security"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-04-16T17:18:13Z"}}