{"id":"GHSA-q7g5-jq6p-6wvx","summary":"Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value","details":"### Impact\nStarting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless.\n\n### Patches\n\n### Workarounds\nDisabling http-based inputs and allow only authenticated pull-based inputs.\n\nAnalysis provided by Fabian Yamaguchi - Whirly Labs (Pty) Ltd","aliases":["CVE-2025-30373"],"modified":"2025-05-07T15:16:44.106738Z","published":"2025-04-07T16:37:52Z","database_specific":{"nvd_published_at":"2025-04-07T15:15:43Z","cwe_ids":["CWE-285"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-04-07T16:37:52Z"},"references":[{"type":"WEB","url":"https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-q7g5-jq6p-6wvx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30373"},{"type":"WEB","url":"https://github.com/Graylog2/graylog2-server/commit/31bc13d3cd6f550ec83473d0f8666cd3ebf50f10"},{"type":"PACKAGE","url":"https://github.com/Graylog2/graylog2-server"}],"affected":[{"package":{"name":"org.graylog2:graylog2-server","ecosystem":"Maven","purl":"pkg:maven/org.graylog2/graylog2-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.1.9"}]}],"versions":["6.1.0","6.1.1","6.1.2","6.1.4","6.1.5","6.1.6","6.1.7","6.1.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-q7g5-jq6p-6wvx/GHSA-q7g5-jq6p-6wvx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"}]}