CVE-2025-30373
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-30373 is a vulnerability affecting Graylog, an open-source log management platform. Starting from version 6.1, Graylog allows HTTP inputs to be configured for authentication based on the presence of a specific header and its value. However, if the header is missing or has an incorrect value, the platform will still return a HTTP 401 response but ingest the message nonetheless, leading to unauthorized access. To mitigate the issue, it is recommended to disable HTTP-based inputs and enable only authenticated pull-based inputs. This vulnerability was fixed in version 6.1.9.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Server