PT-2020-20354 · Misp · Misp

Dawid Czarnecki

·

Published

2020-02-11

·

Updated

2023-09-28

·

CVE-2020-8893

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.4.121
Description An issue was discovered in the Galaxy view, where an incorrectly sanitized search string was found in app/View/Galaxies/view.ctp.
Recommendations For versions prior to 2.4.121, update to version 2.4.121 or later to resolve the issue. As a temporary workaround, consider restricting access to the Galaxy view until the update is applied.

Fix

Related Identifiers

CVE-2020-8893

Affected Products

Misp