Filtered by vendor Graylog
Subscribe
Total
6 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-37760 | 1 Graylog | 1 Graylog | 2021-08-10 | 7.5 HIGH | 9.8 CRITICAL |
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID). | |||||
CVE-2021-37759 | 1 Graylog | 1 Graylog | 2021-08-10 | 7.5 HIGH | 9.8 CRITICAL |
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID). | |||||
CVE-2020-15813 | 1 Graylog | 1 Graylog | 2020-07-22 | 6.8 MEDIUM | 8.1 HIGH |
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connection configuration allows the usage of unencrypted, SSL- or TLS-secured connections. Unfortunately, the Graylog client code (in all versions that support LDAP) does not implement proper certificate validation (regardless of whether the "Allow self-signed certificates" option is used). Therefore, any attacker with the ability to intercept network traffic between a Graylog server and an LDAP server is able to redirect traffic to a different LDAP server (unnoticed by the Graylog server due to the lack of certificate validation), effectively bypassing Graylog's authentication mechanism. | |||||
CVE-2018-14380 | 1 Graylog | 1 Graylog | 2018-09-14 | 4.3 MEDIUM | 6.1 MEDIUM |
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts. | |||||
CVE-2018-11651 | 1 Graylog | 1 Graylog | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx. | |||||
CVE-2018-11650 | 1 Graylog | 1 Graylog | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js. |