Vulnerabilities > Graylog

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-24823 Unspecified vulnerability in Graylog
Graylog is a free and open log management platform.
network
high complexity
graylog
4.4
2024-02-07 CVE-2024-24824 Incorrect Authorization vulnerability in Graylog
Graylog is a free and open log management platform.
network
low complexity
graylog CWE-863
8.8
2023-08-31 CVE-2023-41044 Unspecified vulnerability in Graylog 5.1.0/5.1.1/5.1.2
Graylog is a free and open log management platform.
network
low complexity
graylog
3.8
2023-08-31 CVE-2023-41045 Unspecified vulnerability in Graylog
Graylog is a free and open log management platform.
network
low complexity
graylog
5.3
2023-08-30 CVE-2023-41041 Unspecified vulnerability in Graylog
Graylog is a free and open log management platform.
network
high complexity
graylog
3.1
2021-07-31 CVE-2021-37759 Information Exposure Through Log Files vulnerability in Graylog
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
network
low complexity
graylog CWE-532
critical
9.8
2021-07-31 CVE-2021-37760 Information Exposure Through Log Files vulnerability in Graylog
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
network
low complexity
graylog CWE-532
critical
9.8
2020-07-17 CVE-2020-15813 Improper Certificate Validation vulnerability in Graylog
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.
network
high complexity
graylog CWE-295
8.1
2018-07-18 CVE-2018-14380 Cross-site Scripting vulnerability in Graylog
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
network
low complexity
graylog CWE-79
6.1
2018-06-01 CVE-2018-11651 Cross-site Scripting vulnerability in Graylog
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
network
low complexity
graylog CWE-79
6.1