GHSA-q7g5-jq6p-6wvx

Suggest an improvement
Source
https://github.com/advisories/GHSA-q7g5-jq6p-6wvx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-q7g5-jq6p-6wvx/GHSA-q7g5-jq6p-6wvx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q7g5-jq6p-6wvx
Aliases
Published
2025-04-07T16:37:52Z
Modified
2025-05-07T15:16:44Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
Details

Impact

Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless.

Patches

Workarounds

Disabling http-based inputs and allow only authenticated pull-based inputs.

Analysis provided by Fabian Yamaguchi - Whirly Labs (Pty) Ltd

Database specific
{
    "cwe_ids":  [
        "CWE-285"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-04-07T16:37:52Z",
    "nvd_published_at":  "2025-04-07T15:15:43Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.graylog2:graylog2-server

Package

Name
org.graylog2:graylog2-server
View open source insights on deps.dev
Purl
pkg:maven/org.graylog2/graylog2-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.1.9

Affected versions

6.*
6.1.0
6.1.1
6.1.2
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-q7g5-jq6p-6wvx/GHSA-q7g5-jq6p-6wvx.json"