CVE-2021-31780

MISP/MISP
on github

Published

Severity

CVSS v3:
7.5 HIGH
CVSS v2:
5 MEDIUM

Description

In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:misp:misp:2.4.141:*:*:*:*:*:*:*n/an/a2.4.141

External Links