SCA: security update for org.graylog:graylog-parent (GHSA-vggm-3478-vm5m)

high Tenable Self-Hosted Container Security Plugin ID 419325

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Graylog is a free and open log management platform. The reporting functionality in Graylog allows the
creation and scheduling of reports which contain dashboard widgets displaying individual log messages or
metrics aggregated from fields of multiple log messages. This functionality, as included in Graylog 6.1.0
& 6.1.1, is vulnerable to information leakage triggered by multiple concurrent report rendering requests
from authorized users. When multiple report renderings are requested at the same start time, the headless
browser instance used to render the PDF will be reused. Depending on the timing, either a check for the
browser instance "freshness" hits, resulting in an error instead of the report being returned, or one of
the concurrent report rendering requests "wins" and this report is returned for all report rendering
requests that do not return an error. This might lead to one user getting the report of a different user,
potentially leaking indexed log messages or aggregated data that this user normally has no access to. This
problem is fixed in Graylog 6.1.2. There is no known workaround besides disabling the reporting
functionality. (CVE-2024-52506)

See Also

https://github.com/advisories/GHSA-vggm-3478-vm5m

Plugin Details

Severity: High

ID: 419325

Version: Revision 1.13

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2024-52506

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.1

Threat Score: 5.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/18/2024

Vulnerability Publication Date: 11/18/2024

Reference Information

CVE: CVE-2024-52506

cwe: CWE-200