Executive brief
Graylog Web Interface is a web-based user interface component for the Graylog log management platform. The software contains output encoding flaws in its TypeAhead and QueryInput components, allowing attackers to inject and execute arbitrary JavaScript code in victims' browsers. An attacker could steal session tokens, capture user credentials, or perform actions on behalf of the victim.
Technical details
This is a Cross-Site Scripting (CWE-79) vulnerability affecting all versions of graylog-web-interface. The TypeAhead and QueryInput components fail to properly escape user-supplied input, allowing attackers to inject malicious JavaScript. The vulnerability is reachable via the web interface without authentication requirements. An attacker can craft a malicious link or input containing JavaScript payloads that execute in the victim's browser with the victim's privileges, potentially leading to session hijacking, credential theft, or unauthorized actions. No fix is currently available according to the advisory.
Affected products
- Graylog Web Interface all versions
Timeline
- 2020-09-03: disclosed