GraylogGHSA-q7g5-jq6p-6wvx
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
Medium6.5CVE-2025-30373 · Published Apr 7, 2025 · updated May 7, 2025
### Impact Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. ### Patches ### Workarounds Disabling http-based inputs and allow only authenticated pull-based inputs. Analysis provided by Fabian Yamaguchi - Whirly Labs (Pty) Ltd
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.graylog2:graylog2-server Maven | >= 6.1.0, < 6.1.9 | 6.1.9 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-285
- Also known as
- CVE-2025-30373
More Graylog advisories
All Graylog| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields | Medium5.0 | 7.1.4 |
| Jun 302025 | Graylog vulnerable to privilege escalation through API tokens | High | 6.2.4+1 more |
| May 72025 | Graylog Allows Session Takeover via Insufficient HTML Sanitization | High8.0 | 6.0.14+1 more |
| May 72025 | Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser | High7.3 | 6.2.0 |
| Feb 72024 | Graylog session fixation vulnerability through cookie injection | Medium5.7 | 5.1.11+1 more |
| Feb 72024 | Graylog vulnerable to instantiation of arbitrary classes triggered by API request | High8.8 | 5.1.11+1 more |