graylog2-serverGHSA-38hf-xjmx-jrh8
Cross-site Scripting in Graylog Server
Medium6.1CVE-2018-14380 · Published May 14, 2022 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.graylog2:graylog2-server Maven | < 2.4.6 | 2.4.6 |
Details and references
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2018-14380
More graylog2-server advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 142022 | Cross-site Scripting in Graylog CVE-2018-11651Medium6.1fixed in 2.4.4 | Medium6.1 | 2.4.4 |
| May 142022 | Cross-site Scripting in Graylog Server CVE-2018-11650Medium6.1fixed in 2.4.4 | Medium6.1 | 2.4.4 |
| Jul 62023 | Graylog user session is still usable after logout CVE-2023-41041Low2.6fixed in 5.0.9, 5.1.3 | Low2.6 | 5.0.9, 5.1.3 |
| Jul 62023 | Graylog vulnerable to insecure source port usage for DNS queries CVE-2023-41045Low3.7fixed in 5.0.9, 5.1.3 | Low3.7 | 5.0.9, 5.1.3 |
| Jul 62023 | Graylog server has partial path traversal vulnerability in Support Bundle feature CVE-2023-41044Low3.3fixed in 5.1.3 | Low3.3 | 5.1.3 |
| Feb 72024 | Graylog vulnerable to instantiation of arbitrary classes triggered by API request CVE-2024-24824High8.8fixed in 5.1.11, 5.2.4 | High8.8 | 5.1.11, 5.2.4 |