9.8
CVE-2021-37759
- EPSS 0.5%
- Veröffentlicht 31.07.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:52
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.633 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.