Vulnerabilities > Graylog
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-07 | CVE-2024-24823 | Session Fixation vulnerability in Graylog Graylog is a free and open log management platform. | 4.4 |
2024-02-07 | CVE-2024-24824 | Incorrect Authorization vulnerability in Graylog Graylog is a free and open log management platform. | 8.8 |
2023-08-31 | CVE-2023-41044 | Path Traversal vulnerability in Graylog 5.1.0/5.1.1/5.1.2 Graylog is a free and open log management platform. | 3.8 |
2023-08-31 | CVE-2023-41045 | Insufficient Verification of Data Authenticity vulnerability in Graylog Graylog is a free and open log management platform. | 5.3 |
2023-08-30 | CVE-2023-41041 | Insufficient Session Expiration vulnerability in Graylog Graylog is a free and open log management platform. | 3.1 |
2021-07-31 | CVE-2021-37759 | Information Exposure Through Log Files vulnerability in Graylog A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID). | 7.5 |
2021-07-31 | CVE-2021-37760 | Information Exposure Through Log Files vulnerability in Graylog A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID). | 7.5 |
2020-07-17 | CVE-2020-15813 | Improper Certificate Validation vulnerability in Graylog Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. | 6.8 |
2018-07-18 | CVE-2018-14380 | Cross-site Scripting vulnerability in Graylog In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts. | 4.3 |
2018-06-01 | CVE-2018-11651 | Cross-site Scripting vulnerability in Graylog Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx. | 4.3 |