PT-2021-17658 · Misp · Misp

Jeroen Pinoy

·

Published

2021-03-02

·

Updated

2021-03-08

·

CVE-2021-27904

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: MISP version 2.4.139
Description: An issue was discovered in the implementation of Sharing Groups, where the all org flag sometimes provided view access to unintended actors. This occurred due to a problem in the app/Model/SharingGroupServer.php file.
Recommendations: For MISP version 2.4.139, consider restricting access to the Sharing Groups feature until a patch is available. As a temporary workaround, review and adjust the all org flag settings to ensure they are correctly configured and not providing unintended access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-27904

Affected Products

Misp