Vulnerability Description
In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Misp | Misp | 2.4.87 |
Related Weaknesses (CWE)
References
- https://github.com/MISP/MISP/commit/0a2aa9d52492d960b9a161160acedbe9caaa4126PatchThird Party Advisory
- https://github.com/MISP/MISP/commit/0a2aa9d52492d960b9a161160acedbe9caaa4126PatchThird Party Advisory
FAQ
What is CVE-2018-6926?
CVE-2018-6926 is a vulnerability with a CVSS score of 7.2 (HIGH). In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enable...
How severe is CVE-2018-6926?
CVE-2018-6926 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-6926?
Check the references section above for vendor advisories and patch information. Affected products include: Misp Misp.