PT-2018-15158 · Misp · Misp
Tm9Jdglz
·
Publicado
2018-12-06
·
Atualizado
2019-10-03
·
CVE-2018-19908
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MISP versions 2.4.9x through 2.4.98
Description
An issue was discovered in the STIX 1 import code of MISP, where an unescaped filename string is used to construct a shell command. This can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.
Recommendations
For MISP versions 2.4.9x through 2.4.98, update to version 2.4.99 or later to resolve the issue. As a temporary workaround, consider restricting access to the STIX import functionality to minimize the risk of exploitation.
Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Misp