In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
| Software | From | Fixed in |
|---|---|---|
| graylog / graylog | - | 2.4.6 |
org.graylog2 / graylog2-server
|
- | 2.4.6 |