A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
The product writes sensitive information to a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Graylog | Graylog | 0.20.0 (including) | 4.1.2 (excluding) |