Description
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
Remediation
References
https://github.com/Graylog2/graylog2-server/pull/4727
https://www.graylog.org/post/announcing-graylog-v2-4-4
Related Vulnerabilities
CVE-2019-15782 Vulnerability in maven package org.webjars.npm:webtorrent
CVE-2016-10735 Vulnerability in maven package org.webjars:bootstrap
CVE-2021-3859 Vulnerability in maven package io.undertow:undertow-core
CVE-2018-14380 Vulnerability in npm package graylog-web-interface
CVE-2021-41182 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui