Skip to content
GraylogGHSA-435g-r2m8-gjvm

Cross-site Scripting in Graylog

Medium6.1CVE-2018-11651 · Published May 14, 2022 · updated Nov 8, 2023

Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.graylog2:graylog2-server
Maven
< 2.4.42.4.4
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2018-11651

More Graylog advisories

All Graylog
Advisory
Graylog vulnerable to instantiation of arbitrary classes triggered by API request
High8.8Feb 7, 2024
Graylog server has partial path traversal vulnerability in Support Bundle feature
Low3.3Jul 6, 2023
Graylog vulnerable to insecure source port usage for DNS queries
Low3.7Jul 6, 2023
Graylog user session is still usable after logout
Low2.6Jul 6, 2023
Cross-site Scripting in Graylog Server
Medium6.1May 14, 2022
Cross-site Scripting in Graylog Server
Medium6.1May 14, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.