Junglewise Threat Intelligence

Graylog Web Interface cross-site scripting in TypeAhead and QueryInput

Severity: info · Published 2020-09-03

Vendors: Graylog, npm.

Executive brief

Graylog Web Interface is a web-based user interface component for the Graylog log management platform. The software contains output encoding flaws in its TypeAhead and QueryInput components, allowing attackers to inject and execute arbitrary JavaScript code in victims' browsers. An attacker could steal session tokens, capture user credentials, or perform actions on behalf of the victim.

Technical details

This is a Cross-Site Scripting (CWE-79) vulnerability affecting all versions of graylog-web-interface. The TypeAhead and QueryInput components fail to properly escape user-supplied input, allowing attackers to inject malicious JavaScript. The vulnerability is reachable via the web interface without authentication requirements. An attacker can craft a malicious link or input containing JavaScript payloads that execute in the victim's browser with the victim's privileges, potentially leading to session hijacking, credential theft, or unauthorized actions. No fix is currently available according to the advisory.

Affected products

  • Graylog Web Interface all versions

Timeline

  • 2020-09-03: disclosed

References