PT-2020-20351 · Misp · Misp

Dawid Czarnecki

·

Published

2020-02-11

·

Updated

2020-02-14

·

CVE-2020-8890

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.4.121
Description The issue arises from mishandling time skew between the machine hosting the web server and the machine hosting the database when attempting to block a series of invalid requests, potentially leading to brute-force attacks.
Recommendations For versions prior to 2.4.121, update to version 2.4.121 or later to resolve the issue.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8890

Affected Products

Misp