-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.graylog:graylog-parent | maven | >= 6.1.0, < 6.1.2 | 6.1.2 |
The vulnerability stems from improper management of headless browser instances during concurrent report generation. The ReportService.renderReport function likely coordinates rendering requests while PDFRenderer.generate handles the actual PDF generation. The system's failure to maintain proper instance isolation between concurrent requests suggests missing synchronization mechanisms or shared state management in these components. The high confidence for ReportService reflects its role in request coordination, while medium confidence for PDFRenderer acknowledges potential implementation variations in browser instance handling.
A Semantic Attack on Google Gemini - Read the Latest Research