CVE-2018-11651: XSS
Published Jun 1, 2018
·Updated
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
Affected Software
1 affected component
Graylog Graylog<2.4.4
Remediation
Patch Available
Event History
Jun 1, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11651?
CVE-2018-11651 refers to an XSS security issue in Graylog before v2.4.4, related to unescaped text in dashboard names.
2
How does CVE-2018-11651 affect Graylog?
CVE-2018-11651 affects Graylog versions before v2.4.4 and allows for unescaped text in dashboard names, leading to an XSS security issue.
3
What is the severity of CVE-2018-11651?
CVE-2018-11651 has a severity rating of medium (6.1).
4
How can I fix CVE-2018-11651 in Graylog?
To fix CVE-2018-11651, it is recommended to upgrade Graylog to version 2.4.4 or later.
5
Where can I find more information about CVE-2018-11651?
More information about CVE-2018-11651 can be found in the Graylog GitHub pull request and the official Graylog blog post.