Vulnerabilities > Graylog > Graylog > 3.1.3

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-24824 Incorrect Authorization vulnerability in Graylog
Graylog is a free and open log management platform.
network
low complexity
graylog CWE-863
8.8
2023-08-31 CVE-2023-41045 Unspecified vulnerability in Graylog
Graylog is a free and open log management platform.
network
low complexity
graylog
5.3
2023-08-30 CVE-2023-41041 Unspecified vulnerability in Graylog
Graylog is a free and open log management platform.
network
high complexity
graylog
3.1
2021-07-31 CVE-2021-37759 Information Exposure Through Log Files vulnerability in Graylog
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
network
low complexity
graylog CWE-532
critical
9.8
2021-07-31 CVE-2021-37760 Information Exposure Through Log Files vulnerability in Graylog
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
network
low complexity
graylog CWE-532
critical
9.8
2020-07-17 CVE-2020-15813 Improper Certificate Validation vulnerability in Graylog
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.
network
high complexity
graylog CWE-295
8.1