PT-2025-15234 · Graylog · Graylog

Published

2025-04-07

·

Updated

2025-04-08

·

CVE-2025-30373

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Graylog versions 6.1 through 6.1.8
Description The issue concerns the authentication mechanism for HTTP-based ingestion in Graylog. Even when a specified header is missing or has an incorrect value, the system returns the correct HTTP response (401) but still ingests the message. This behavior allows unauthorized access to the log management platform.
Recommendations For Graylog versions 6.1 through 6.1.8, disable HTTP-based inputs and allow only authenticated pull-based inputs as a mitigation measure. Update to version 6.1.9 to fully resolve the issue.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30373
GHSA-Q7G5-JQ6P-6WVX

Affected Products

Graylog