A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
The product writes sensitive information to a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Graylog | Graylog | 2.1.1 (including) | 4.1.2 (excluding) |