CVE-2021-37759: Critical severity Graylog Graylog vulnerability
Published Jul 31, 2021
·Updated
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
Affected Software
1 affected component
Graylog Graylog>=0.20.0<4.1.2
Event History
Jul 31, 2021
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Graylog vulnerability?
The vulnerability ID for this Graylog vulnerability is CVE-2021-37759.
2
What is the severity of CVE-2021-37759?
CVE-2021-37759 has a severity rating of 9.8 (critical).
3
What is the affected software for CVE-2021-37759?
The affected software for CVE-2021-37759 is Graylog versions before 4.1.2.
4
What can attackers do with CVE-2021-37759?
Attackers can escalate privileges to the access level of the leaked session ID.
5
Is there a fix available for CVE-2021-37759?
Yes, the fix for CVE-2021-37759 is available in Graylog version 4.1.2.