Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10045 | Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. To mitigate the vulnerability, disable http-based inputs and allow only authenticated pull-based inputs. This vulnerability is fixed in 6.1.9. |
Github GHSA |
GHSA-q7g5-jq6p-6wvx | Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value |
Thu, 30 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Graylog
Graylog graylog |
|
| CPEs | cpe:2.3:a:graylog:graylog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Graylog
Graylog graylog |
Tue, 08 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. To mitigate the vulnerability, disable http-based inputs and allow only authenticated pull-based inputs. This vulnerability is fixed in 6.1.9. | |
| Title | Graylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong value | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-08T19:02:45.783Z
Reserved: 2025-03-21T14:12:06.272Z
Link: CVE-2025-30373
Updated: 2025-04-08T19:02:40.264Z
Status : Analyzed
Published: 2025-04-07T15:15:43.887
Modified: 2025-10-30T18:54:24.137
Link: CVE-2025-30373
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA