CVE-2018-11650: XSS
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-11650?
CVE-2018-11650 is an XSS security issue in Graylog before version 2.4.4.
What is the severity of CVE-2018-11650?
The severity of CVE-2018-11650 is medium with a CVSS score of 6.1.
How does CVE-2018-11650 affect Graylog?
CVE-2018-11650 affects Graylog versions before 2.4.4 and introduces an XSS security issue with unescaped text in notifications.
How can I fix the CVE-2018-11650 vulnerability?
To fix the CVE-2018-11650 vulnerability, upgrade Graylog to version 2.4.4 or later.
Where can I find more information about CVE-2018-11650?
You can find more information about CVE-2018-11650 at the following references: [https://github.com/Graylog2/graylog2-server/pull/4727](https://github.com/Graylog2/graylog2-server/pull/4727) and [https://www.graylog.org/post/announcing-graylog-v2-4-4](https://www.graylog.org/post/announcing-graylog-v2-4-4).