Replies: 1 comment
-
|
The flaw is in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled. UTMStack agent does not uses the httpjson input for any integration that depends on Filebeat, then updating is not required. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Sentinel One is flagging the version of Filebeat.exe used by UTM stack agent. After investigating it seems that the version used is 8.5.3 which has a CVE https://app.opencve.io/cve/CVE-2023-31413
What is the best way to patch this. Will updating the UTM stack agent update filebeat to a later version or should we try to update filebeat directly (assuming that won't break the agent)
Beta Was this translation helpful? Give feedback.
All reactions