CVE-2018-14380: XSS
Published Jul 18, 2018
·Updated
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
Affected Software
1 affected component
Graylog Graylog<2.4.6
Remediation
Event History
Jul 18, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-14380?
CVE-2018-14380 is a vulnerability in Graylog before version 2.4.6 that allows for cross-site scripting (XSS) attacks in typeahead components.
2
How severe is CVE-2018-14380?
CVE-2018-14380 has a severity rating of 6.1, which is considered medium.
3
What software versions are affected by CVE-2018-14380?
Graylog versions up to and excluding 2.4.6 are affected by CVE-2018-14380.
4
How can I fix CVE-2018-14380?
To fix CVE-2018-14380, it is recommended to upgrade to Graylog version 2.4.6 or later.