Description
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
Remediation
References
https://github.com/Graylog2/graylog2-server/pull/4727
https://www.graylog.org/post/announcing-graylog-v2-4-4
Related Vulnerabilities
CVE-2021-26539 Vulnerability in npm package sanitize-html
CVE-2023-26120 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2020-17479 Vulnerability in npm package jpv
CVE-2023-49486 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-23620 Vulnerability in maven package org.xwiki.platform:xwiki-platform-skin-skinx