CVE-2018-6926

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
9
HIGH
Affected
1
PROJECT

Description

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

MISP (core software) - Open Source Threat Intelligence and Sharing Platform
GitHubGitHub
6.38K