CVE-2025-27912
Datalust Seq vulnerability analysis and mitigation

Overview

An issue was discovered in Datalust Seq before 2024.3.13545. The vulnerability (CVE-2025-27912) involves missing Content-Type validation that can lead to Cross-Site Request Forgery (CSRF) attacks. The vulnerability was discovered through Datalust's internal security processes and was disclosed on February 17, 2025. The affected systems include installations of Datalust Seq prior to version 2024.3.13545, with varying scope and impact for versions before Seq 202x (Datalust Issue, NVD).

Technical details

The vulnerability stems from improper Content-Type validation in the authentication mechanism. It can be triggered under two specific conditions: when Entra ID or OpenID Connect authentication is in use and a user visits a compromised/malicious site, or when username/password or Active Directory authentication is in use and a user visits a compromised/malicious site under the same effective top-level domain as the Seq server. The vulnerability has been assigned a CVSS 3.1 score of 8.8 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) (NVD).

Impact

Successful exploitation of the vulnerability allows attackers to conduct impersonation attacks and perform actions in Seq on behalf of the targeted user. The attack requires the user to visit a malicious website while having an authenticated Seq session cookie in their browser (Datalust Issue).

Mitigation and workarounds

All Seq customers are advised to update to Seq version 2024.3.13545 or later as soon as possible. The fixed version is available for download at datalust.co/download or via Docker image datalust/seq:2024.3.13545 (Datalust Issue).

Additional resources


SourceThis report was generated using AI

Related Datalust Seq vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-29866CRITICAL9.1
  • Datalust SeqDatalust Seq
  • cpe:2.3:a:datalust:seq
NoYesMar 21, 2024
CVE-2025-27912HIGH8.8
  • Datalust SeqDatalust Seq
  • cpe:2.3:a:datalust:seq
NoYesMar 11, 2025
CVE-2025-27911MEDIUM6.5
  • Datalust SeqDatalust Seq
  • cpe:2.3:a:datalust:seq
NoYesMar 11, 2025
CVE-2024-58102MEDIUM6.5
  • Datalust SeqDatalust Seq
  • cpe:2.3:a:datalust:seq
NoYesMar 11, 2025
CVE-2023-38195MEDIUM4.9
  • Datalust SeqDatalust Seq
  • cpe:2.3:a:datalust:seq
NoYesJul 22, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management