Skip to content
GraylogGHSA-h7g4-65mf-6mxh

Cross-site Scripting in Graylog Server

Medium6.1CVE-2018-11650 · Published May 14, 2022 · updated Nov 8, 2023

Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.graylog2:graylog2-server
Maven
< 2.4.42.4.4
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2018-11650

More Graylog advisories

All Graylog
Advisory
Graylog vulnerable to instantiation of arbitrary classes triggered by API request
High8.8Feb 7, 2024
Graylog server has partial path traversal vulnerability in Support Bundle feature
Low3.3Jul 6, 2023
Graylog vulnerable to insecure source port usage for DNS queries
Low3.7Jul 6, 2023
Graylog user session is still usable after logout
Low2.6Jul 6, 2023
Cross-site Scripting in Graylog
Medium6.1May 14, 2022
Cross-site Scripting in Graylog Server
Medium6.1May 14, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.