datalust / seq-tickets

Issues, design discussions and feature roadmap for the Seq log server
https://datalust.co/seq
96 stars 5 forks source link

Escalation of privileges vulnerability CVE-2024-29866 #2127

Closed nblumhardt closed 6 months ago

nblumhardt commented 6 months ago

An escalation of privileges vulnerability exists in Seq versions 2022.1.7378 to 2024.1.11028 inclusive.

Servers with:

are affected. These users, and those holding affected API keys, can use them to acquire System permissions.

Datalust recommends upgrading impacted instances to Seq 2024.1.11146 / datalust/seq:2024.1.11146, which is a highly-compatible in-place update for all versions in the affected range.

Servers running Seq 2023.4, which is within its support window, may alternatively upgrade to patch 2023.4.11151 (available via https://datalust.co/download/all, or the corresponding datalust/seq tag), which also addresses the issue.

The issue can also be worked around without upgrading, by:


This issue was identified by Datalust during regular internal testing.