Vulnerability Description
IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in the "send" functionality of the Inspect-tool of the Monitor component. An attacker with access to the IntelMQ Manager could possibly use this issue to execute arbitrary code with the privileges of the webserver. Version 2.1.1 fixes the vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intelmq Manager Project | Intelmq Manager | >= 1.1.0, < 2.1.1 |
Related Weaknesses (CWE)
References
- https://github.com/certtools/intelmq-manager/commit/b9a2ac43a4f99d764b827108f6a9PatchThird Party Advisory
- https://github.com/certtools/intelmq-manager/releases/tag/2.1.1Third Party Advisory
- https://github.com/certtools/intelmq-manager/security/advisories/GHSA-rrhh-rcgp-PatchThird Party Advisory
- https://lists.cert.at/pipermail/intelmq-users/2020-April/000161.htmlThird Party Advisory
- https://github.com/certtools/intelmq-manager/commit/b9a2ac43a4f99d764b827108f6a9PatchThird Party Advisory
- https://github.com/certtools/intelmq-manager/releases/tag/2.1.1Third Party Advisory
- https://github.com/certtools/intelmq-manager/security/advisories/GHSA-rrhh-rcgp-PatchThird Party Advisory
- https://lists.cert.at/pipermail/intelmq-users/2020-April/000161.htmlThird Party Advisory
FAQ
What is CVE-2020-11016?
CVE-2020-11016 is a vulnerability with a CVSS score of 9.1 (CRITICAL). IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in the "send" functionality of the Inspect-tool of th...
How severe is CVE-2020-11016?
CVE-2020-11016 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-11016?
Check the references section above for vendor advisories and patch information. Affected products include: Intelmq Manager Project Intelmq Manager.