Information disclosure in MISP - CVE-2019-9482

 

Information disclosure in MISP - CVE-2019-9482

Published: March 1, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36086
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-9482
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: misp-project.org
Affected software:
MISP

Detailed vulnerability description

The vulnerability allows a remote authenticated user to gain access to sensitive information.

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).


How to mitigate CVE-2019-9482

Install update from vendor's website.

Sources