Skip to content
graylog2-serverGHSA-38hf-xjmx-jrh8

Cross-site Scripting in Graylog Server

Medium6.1CVE-2018-14380 · Published May 14, 2022 · updated Nov 8, 2023

GitHub advisory

Affected versions

PackageAffectedFixed in
org.graylog2:graylog2-server
Maven
< 2.4.62.4.6
Details and references

In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2018-14380

More graylog2-server advisories

All
DateAdvisory
May 142022Cross-site Scripting in Graylog
CVE-2018-11651Medium6.1fixed in 2.4.4
May 142022Cross-site Scripting in Graylog Server
CVE-2018-11650Medium6.1fixed in 2.4.4
Jul 62023Graylog user session is still usable after logout
CVE-2023-41041Low2.6fixed in 5.0.9, 5.1.3
Jul 62023Graylog vulnerable to insecure source port usage for DNS queries
CVE-2023-41045Low3.7fixed in 5.0.9, 5.1.3
Jul 62023Graylog server has partial path traversal vulnerability in Support Bundle feature
CVE-2023-41044Low3.3fixed in 5.1.3
Feb 72024Graylog vulnerable to instantiation of arbitrary classes triggered by API request
CVE-2024-24824High8.8fixed in 5.1.11, 5.2.4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.