Description
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
Remediation
References
https://github.com/Graylog2/graylog2-server/pull/4739
https://www.graylog.org/post/announcing-graylog-v2-4-4
Related Vulnerabilities
CVE-2022-45392 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration
CVE-2023-50571 Vulnerability in maven package org.jeasy:easy-rules-mvel
CVE-2020-15252 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2023-31826 Vulnerability in maven package org.skyscreamer:nevado-jms
CVE-2022-45688 Vulnerability in maven package cn.hutool:hutool-json