PT-2020-13320 · Misp · Misp-Maltego

Published

2020-05-15

·

Updated

2022-05-24

·

CVE-2020-12889

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MISP MISP-maltego version 1.4.4
Description The issue arises from MISP MISP-maltego incorrectly sharing a MISP connection across users in a remote-transform use case. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For version 1.4.4, update to version 1.4.5, which contains a patch for this issue.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12889
GHSA-FJ35-M94R-9H4C
PYSEC-2020-66

Affected Products

Misp-Maltego