GraylogGHSA-435g-r2m8-gjvm
Cross-site Scripting in Graylog
Medium6.1CVE-2018-11651 · Published May 14, 2022 · updated Nov 8, 2023
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.graylog2:graylog2-server Maven | < 2.4.4 | 2.4.4 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2018-11651
More Graylog advisories
All Graylog| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 72024 | Graylog vulnerable to instantiation of arbitrary classes triggered by API request | High8.8 | 5.1.11+1 more |
| Jul 62023 | Graylog server has partial path traversal vulnerability in Support Bundle feature | Low3.3 | 5.1.3 |
| Jul 62023 | Graylog vulnerable to insecure source port usage for DNS queries | Low3.7 | 5.0.9+1 more |
| Jul 62023 | Graylog user session is still usable after logout | Low2.6 | 5.0.9+1 more |
| May 142022 | Cross-site Scripting in Graylog Server | Medium6.1 | 2.4.4 |
| May 142022 | Cross-site Scripting in Graylog Server | Medium6.1 | 2.4.6 |