Graylog

Graylog

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 21.09.2026 17:46:30
  • Zuletzt bearbeitet 24.09.2026 21:17:43

Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grant...

  • EPSS 0.3%
  • Veröffentlicht 16.09.2026 20:32:45
  • Zuletzt bearbeitet 22.09.2026 20:53:07

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoints that redi...

  • EPSS 0.34%
  • Veröffentlicht 28.08.2026 22:14:35
  • Zuletzt bearbeitet 09.09.2026 21:09:13

Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resour...

  • EPSS 0.36%
  • Veröffentlicht 28.08.2026 22:11:08
  • Zuletzt bearbeitet 09.09.2026 21:09:13

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLForti...

  • EPSS 0.3%
  • Veröffentlicht 28.08.2026 18:08:22
  • Zuletzt bearbeitet 09.09.2026 21:09:13

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.jav...

  • EPSS 0.19%
  • Veröffentlicht 18.02.2026 13:14:11
  • Zuletzt bearbeitet 18.02.2026 20:20:16

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...

  • EPSS 0.19%
  • Veröffentlicht 18.02.2026 13:13:51
  • Zuletzt bearbeitet 18.02.2026 20:20:33

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...

  • EPSS 0.18%
  • Veröffentlicht 18.02.2026 13:13:36
  • Zuletzt bearbeitet 18.02.2026 20:20:50

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...

  • EPSS 0.18%
  • Veröffentlicht 18.02.2026 13:13:23
  • Zuletzt bearbeitet 18.02.2026 20:21:08

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...

  • EPSS 0.2%
  • Veröffentlicht 18.02.2026 13:12:57
  • Zuletzt bearbeitet 18.02.2026 20:21:24

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...