PT-2020-20355 · Misp · Misp

Dawid Czarnecki

·

Published

2020-02-11

·

Updated

2023-09-28

·

CVE-2020-8894

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.4.121
Description An issue was discovered where ACLs for discussion threads were mishandled in the ThreadsController.php and Thread.php files.
Recommendations For versions prior to 2.4.121, update to version 2.4.121 or later to resolve the issue.

Fix

Related Identifiers

CVE-2020-8894

Affected Products

Misp