Graylog 是一个免费且开源的日志管理平台。在 7.1.0 至 7.1.4 以及 7.2.0-alpha.2 版本中,位于 中的 System Catalog 实体标题端点允许已认证用户请求组合显示字段,但未验证所选的每个字段是否可读。因此,用户可以获取受保护的值,包括可读用户记录中的密码哈希值;普通用户仅能访问其被授权的用户记录,而管理员则可以获取所有用户的密码哈希值。该问题已在 7.1.4 和 7.2.0-alpha.2 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Graylog2 | graylog2-server | >= 7.1.0, < 7.1.4 |
affected |
>= 7.2.0-alpha.1, < 7.2.0-alpha.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Graylog2 | graylog2-server | >= 7.1.0, < 7.1.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55841 | 7.5 HIGH | Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from |
| CVE-2026-55867 | 5.3 MEDIUM | Graylog token revocation endpoint allows authenticated users to delete other users’ access |
No comments yet