PT-2026-63436 · Graylog2+1 · Graylog2-Server
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Graylog2 Server versions prior to commit 46a2eeb
Description
An issue exists where a per-entity permission check is missing in the 'POST /events/definitions/{definitionId}/duplicate' endpoint. This allows authenticated users with the
eventdefinitions:create capability to clone any event definition. By duplicating these definitions, attackers can read private information, including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings.Recommendations
Update Graylog2 Server to commit 46a2eeb or a later version.
Restrict the use of the
eventdefinitions:create capability to trusted users until the update is applied.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Graylog2-Server