Path Traversal: \'../filedir\' in Graylog - CVE-2023-41044

 

Path Traversal: \'../filedir\' in Graylog - CVE-2023-41044

Published: July 5, 2023 / Updated: June 25, 2026


Vulnerability identifier: #VU135308
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41044
CWE-ID: CWE-24
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information or delete files.

The vulnerability exists due to path traversal in the Support Bundle HTTP API resource when handling crafted filename parameters. A remote user can send a specially crafted request to disclose sensitive information or delete files.

Exploitation requires valid Admin role credentials and is limited to sibling directories whose names begin with the support bundle directory path.


Affected software

Graylog

How to mitigate CVE-2023-41044

Install security update from vendor's website.

Graylog - update to 5.1.3

External References

Related Security Bulletins