Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or leaked 'sessionId' can continue to be used to authenticate valid requests. Exploiting this vulnerability would allow an attacker with access to the web service/API network (port 9000 or HTTP/S endpoint of the server) to reuse an old session token to gain unauthorized access to the application, interact with the API/web, and compromise the integrity of the affected account.
The application generates a new session identifier ('sessionId') during each user authentication, however old session identifiers are not invalidated and remain active. An attacker who obtains a previously issued session token (e.g., through interception or a leak) can use it multiple times to authenticate requests to the API or web interface. The attack requires network access to the Graylog service on port 9000 or through the HTTP/HTTPS endpoint of the server.
An attacker can gain unauthorized access to the Graylog application, perform operations on the API and web interface, and compromise the integrity and confidentiality of the attacked user's account.
Apply patches available from the vendor according to the references (https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-graylog). Additionally, it is recommended to force user re-authentication and audit active sessions to eliminate potentially compromised tokens.
Graylog Web Interface version 2.2.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XGraylog
APPGraylog2.2.3
Related vulnerabilities
Wyciek Session ID w logach DEBUG w Graylog — eskalacja uprawnień
Wyciek Session ID w logu audytu Graylog — privilege escalation
Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in t...
Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to bef...
Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possibl...