CVE-2023-41041
- EPSS 0.41%
- Veröffentlicht 30.08.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:20:26
Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged out, a user session may still be used for API requests until it has reached its original expiry time. Each node maintains an in-me...
CVE-2021-37760
- EPSS 1.29%
- Veröffentlicht 31.07.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:52
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
CVE-2021-37759
- EPSS 1.29%
- Veröffentlicht 31.07.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:52
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
CVE-2020-15813
- EPSS 0.78%
- Veröffentlicht 17.07.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:13
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connection configuration allows the usage of unencrypted, SSL- or TLS-secured connections. Unfortunately, the...
CVE-2018-14380
- EPSS 0.98%
- Veröffentlicht 18.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:57
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
CVE-2018-11650
- EPSS 0.85%
- Veröffentlicht 01.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:46
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
CVE-2018-11651
- EPSS 0.81%
- Veröffentlicht 01.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:46
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.