Graylog
by Graylog
Source repositories
CVEs (24)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14380 | Med | 0.00 | 6.1 | 0.01 | Jul 18, 2018 | In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts. | ||
| CVE-2018-11651 | Med | 0.00 | 6.1 | 0.01 | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx. | ||
| CVE-2018-11650 | Med | 0.00 | 6.1 | 0.01 | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js. | ||
| CVE-2014-9217 | 0.00 | — | 0.02 | Dec 8, 2014 | Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards. |
- risk 0.00cvss 6.1epss 0.01
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
- risk 0.00cvss 6.1epss 0.01
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
- risk 0.00cvss 6.1epss 0.01
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
- CVE-2014-9217Dec 8, 2014risk 0.00cvss —epss 0.02
Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.
Page 2 of 2