Required CVE Record Information
Description
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://github.com/Graylog2/graylog2-server/pull/4739 x_transferred
- https://www.graylog.org/post/announcing-graylog-v2-4-4 x_transferred