SCA: security update for org.graylog2:graylog2-server (GHSA-3xf8-g8gr-g7rh)

medium Tenable Self-Hosted Container Security Plugin ID 409783

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11
and 5.2.4, reauthenticating with an existing session cookie would re-use that session id, even if for
different user credentials. In this case, the pre-existing session could be used to gain elevated access
to an existing Graylog login session, provided the malicious user could successfully inject their session
cookie into someone else's browser. The complexity of such an attack is high, because it requires
presenting a spoofed login screen and injection of a session cookie into an existing browser, potentially
through a cross-site scripting attack. No such attack has been discovered. Graylog 5.1.11 and 5.2.4, and
any versions of the 6.0 development branch, contain patches to not re-use sessions under any
circumstances. Some workarounds are available. Using short session expiration and explicit log outs of
unused sessions can help limiting the attack vector. Unpatched this vulnerability exists, but is
relatively hard to exploit. A proxy could be leveraged to clear the `authentication` cookie for the
Graylog server URL for the `/api/system/sessions` endpoint, as that is the only one vulnerable.
(CVE-2024-24823)

See Also

https://github.com/advisories/GHSA-3xf8-g8gr-g7rh

Plugin Details

Severity: Medium

ID: 409783

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.14

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.7

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2024-24823

CVSS v3

Risk Factor: Medium

Base Score: 4.4

Temporal Score: 3.9

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/7/2024

Vulnerability Publication Date: 2/7/2024

Reference Information

CVE: CVE-2024-24823

cwe: CWE-384