ZeroHour

CVE-2021-37759

CVSS 3.1
9.8 critical
EPSS
1%p68
Published
()
Modified
Description

A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).

Vendors
graylog
Products
graylog
Weakness
CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.