Executive brief
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
Affected products
- Maven org.graylog2:graylog2-server
Junglewise Threat Intelligence
CVE-2025-30373 · Severity: low · CVSS 3.1 · Published 2025-04-07
Technologies: org.graylog2:graylog2-server (Maven). Vendors: Maven.
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value