4.3
CVSS V3
Status
Fixed version
8.15.0-r0Status
Impact
Logstash bundles an old version of jruby v3.1.0 which installs a vulnerable version of rexml. Upstream jruby should fix this vulnerability for this version as it updates its default gems on some next release.
Status