MEDIUMMaven →
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
Affected packages
- org.graylog2:graylog2-server— 7.1.0 → 7.1.4
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-q79r-r9xg-r863
- https://github.com/Graylog2/graylog2-server/pull/26284
- https://github.com/Graylog2/graylog2-server/commit/1d1a91d99c3d2d8993e61c3c52344648163d3a21
- https://github.com/Graylog2/graylog2-server/commit/da7767a44233b6a683d0713eed08da31ce0e77b5
- https://github.com/Graylog2/graylog2-server
- https://github.com/Graylog2/graylog2-server/releases/tag/7.1.4
- https://github.com/Graylog2/graylog2-server/releases/tag/7.2.0-alpha.2
Structured record: https://osv.dev/vulnerability/GHSA-q79r-r9xg-r863
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta