Vulnerabilities > Graylog

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-24823 Session Fixation vulnerability in Graylog
Graylog is a free and open log management platform.
network
high complexity
graylog CWE-384
4.4
2024-02-07 CVE-2024-24824 Incorrect Authorization vulnerability in Graylog
Graylog is a free and open log management platform.
network
low complexity
graylog CWE-863
8.8
2023-08-31 CVE-2023-41044 Path Traversal vulnerability in Graylog 5.1.0/5.1.1/5.1.2
Graylog is a free and open log management platform.
network
low complexity
graylog CWE-22
3.8
2023-08-31 CVE-2023-41045 Insufficient Verification of Data Authenticity vulnerability in Graylog
Graylog is a free and open log management platform.
network
low complexity
graylog CWE-345
5.3
2023-08-30 CVE-2023-41041 Insufficient Session Expiration vulnerability in Graylog
Graylog is a free and open log management platform.
network
high complexity
graylog CWE-613
3.1
2021-07-31 CVE-2021-37759 Information Exposure Through Log Files vulnerability in Graylog
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
network
low complexity
graylog CWE-532
7.5
2021-07-31 CVE-2021-37760 Information Exposure Through Log Files vulnerability in Graylog
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
network
low complexity
graylog CWE-532
7.5
2020-07-17 CVE-2020-15813 Improper Certificate Validation vulnerability in Graylog
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.
network
graylog CWE-295
6.8
2018-07-18 CVE-2018-14380 Cross-site Scripting vulnerability in Graylog
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
network
graylog CWE-79
4.3
2018-06-01 CVE-2018-11651 Cross-site Scripting vulnerability in Graylog
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
network
graylog CWE-79
4.3