Impact
Graylog servers up to version 7.1.4 validate outbound URLs against an allowlist before initiating requests, but the validation is not repeated after an HTTP redirect. A malicious actor can create a lookup table or event notification entry that points to an allowlisted endpoint which then redirects to an internal service. The server follows the redirect, fetches the internal response, and returns it back to the attacker. This flaw allows disclosure of internal responses and can facilitate further internal reconnaissance or exploitation.
Affected Systems
The vulnerability affects the Graylog2:graylog2-server product, specifically any release through and including version 7.1.4. All installations that have not applied the 7.1.5 release, where the redirect validation was corrected, remain vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as a moderate‑severity S2R door. The EPSS score of <1% indicates a low but nonzero probability of active exploitation at the time of analysis, and the flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess lookup table or event‑notification permissions, which are not universally granted by default. Once those permissions are available, the attacker can drive the server to reflect internal network data, potentially exposing sensitive endpoints or service accounts. The attack vector is network‑based, leveraging Graylog’s API or UI, and does not permit arbitrary code execution or direct compromise of the host.
OpenCVE Enrichment