Vulnerability Description
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Misp | Misp | < 2.4.197 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-45509?
CVE-2024-45509 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
How severe is CVE-2024-45509?
CVE-2024-45509 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-45509?
Check the references section above for vendor advisories and patch information. Affected products include: Misp Misp.