Improper Authorization Affecting org.graylog2:graylog2-server package, versions [6.2.0, 6.2.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGGRAYLOG2-10571076
  • published1 Jul 2025
  • disclosed30 Jun 2025
  • creditOthello Maurer

Introduced: 30 Jun 2025

NewCVE-2025-53106  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade org.graylog2:graylog2-server to version 6.2.4 or higher.

Overview

org.graylog2:graylog2-server is a log management platform.

Affected versions of this package are vulnerable to Improper Authorization via an incorrect permission check in the token creation process. An attacker can gain elevated privileges by crafting requests to the REST API and creating API tokens for higher-privileged users if they know the user ID.

Note: This is only exploitable if the attacker has a valid user account in the system.

Workaround

This vulnerability can be mitigated by disabling the option that allows regular users to create personal access tokens in the configuration settings under System > Configuration > Users > "Allow users to create personal access tokens"

CVSS Base Scores

version 4.0
version 3.1