CVE-2021-37760: Critical severity Graylog Graylog vulnerability
Published Jul 31, 2021
·Updated
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
Affected Software
1 affected component
Graylog Graylog>=2.1.1<4.1.2
Event History
Jul 31, 2021
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37760?
CVE-2021-37760 is a vulnerability in Graylog before version 4.1.2 that allows attackers to escalate privileges by exploiting a Session ID leak in the audit log.
2
How severe is CVE-2021-37760?
CVE-2021-37760 has a severity rating of 9.8 (critical).
3
How can an attacker exploit CVE-2021-37760?
An attacker can exploit CVE-2021-37760 by leveraging the Session ID leak in the audit log to escalate their access privileges.
4
Is there a fix for CVE-2021-37760?
Yes, a fix for CVE-2021-37760 is available in Graylog version 4.1.2 and later.
5
Where can I find more information about CVE-2021-37760?
You can find more information about CVE-2021-37760 on the Graylog website: https://www.graylog.org/post/announcing-graylog-v4-1-2