Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.
{
"github_reviewed": true,
"nvd_published_at": "2014-07-22T14:55:00Z",
"severity": "HIGH",
"github_reviewed_at": "2025-04-14T16:59:20Z",
"cwe_ids": [
"CWE-78"
]
}