Vulnerability Description
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Graylog | Graylog | < 2.4.6 |
Related Weaknesses (CWE)
References
- https://github.com/Graylog2/graylog2-server/pull/4904Third Party Advisory
- https://www.graylog.org/post/announcing-the-release-of-graylog-2-4-6PatchRelease NotesVendor Advisory
- https://github.com/Graylog2/graylog2-server/pull/4904Third Party Advisory
- https://www.graylog.org/post/announcing-the-release-of-graylog-2-4-6PatchRelease NotesVendor Advisory
FAQ
What is CVE-2018-14380?
CVE-2018-14380 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
How severe is CVE-2018-14380?
CVE-2018-14380 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14380?
Check the references section above for vendor advisories and patch information. Affected products include: Graylog Graylog.