ZeroHour

CVE-2021-37760

CVSS 3.1
9.8 critical
EPSS
1%p68
Published
()
Modified
Description

A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).

Vendors
graylog
Products
graylog
Weakness
CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.