Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

David Herbstmann

#13786of 53,633
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2021-21863
9.8
2021-07-31
Graylog · Graylog · CVE-2021-37759
Name of the Vulnerable Software and Affected Versions: Graylog versions prior to 4.1.2 Description: A Session ID leak in the DEBUG log file allows attackers to escalate privileges to the access level of the leaked session ID. Recommendations: For Graylog versions prior to 4.1.2, update to version 4.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the DEBUG log file to minimize the risk of exploitation.
PT-2021-21865
9.8
2021-07-31
Graylog · Graylog · CVE-2021-37760
Name of the Vulnerable Software and Affected Versions: Graylog versions prior to 4.1.2 Description: A Session ID leak in the audit log allows attackers to escalate privileges to the access level of the leaked session ID. Recommendations: For versions prior to 4.1.2, update to version 4.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the audit log to minimize the risk of exploitation.