Junglewise Threat Intelligence

CVE-2025-30373: Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value

CVE-2025-30373 · Severity: low · CVSS 3.1 · Published 2025-04-07

Technologies: org.graylog2:graylog2-server (Maven). Vendors: Maven.

Executive brief

Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value

Affected products

  • Maven org.graylog2:graylog2-server

Related threats