Vulnerability Description
In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Misp | Misp | 2.4.102 |
Related Weaknesses (CWE)
References
- https://github.com/MISP/MISP/commit/c69969329d197bcdd04832b03310fa73f4eb7155PatchThird Party Advisory
- https://github.com/MISP/MISP/commit/c69969329d197bcdd04832b03310fa73f4eb7155PatchThird Party Advisory
FAQ
What is CVE-2019-9482?
CVE-2019-9482 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances...
How severe is CVE-2019-9482?
CVE-2019-9482 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9482?
Check the references section above for vendor advisories and patch information. Affected products include: Misp Misp.