Information disclosure in MISP - CVE-2019-9482

 

Information disclosure in MISP - CVE-2019-9482

Published: March 1, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36086
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9482
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).


Affected software

MISP

How to mitigate CVE-2019-9482

Install update from vendor's website.


External References

Related Security Bulletins