Weak password requirements in MISP - CVE-2021-25323

 

Weak password requirements in MISP - CVE-2021-25323

Published: January 19, 2021 / Updated: February 9, 2021


Vulnerability identifier: #VU50443
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25323
CWE-ID: CWE-521
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to perform unauthorized password change.

The vulnerability exists due to the default MISP setting did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password. An attacker with access to the current victim's session set a new password for the victim's account.


Affected software

MISP

How to mitigate CVE-2021-25323

Install updates from vendor's website.

MISP - update to 2.4.137

External References

Related Security Bulletins