Description
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2277 | Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx. |
Github GHSA |
GHSA-435g-r2m8-gjvm | Cross-site Scripting in Graylog |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T04:15:18.598Z
Reserved: 2018-06-01T00:00:00.000Z
Link: CVE-2018-11651
No data.
Status : Modified
Published: 2018-06-01T14:29:00.410
Modified: 2024-11-21T03:43:46.517
Link: CVE-2018-11651
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA