PT-2020-17082 · Misp · Misp

Published

2020-11-24

·

Updated

2020-12-03

·

CVE-2020-29006

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.4.135
Description The issue is related to a lack of an ACL check in MISP, specifically in the app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php files.
Recommendations For versions prior to 2.4.135, update to version 2.4.135 or later to resolve the issue.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29006

Affected Products

Misp