PT-2022-19684 · Misp · Misp

Dawid

·

Published

2022-04-20

·

Updated

2024-02-01

·

CVE-2022-29534

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.4.158
Description An issue was discovered in the UsersController.php file, where password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
Recommendations For versions prior to 2.4.158, update to version 2.4.158 or later to resolve the issue. As a temporary workaround, consider restricting access to the UsersController.php file or disabling the password confirmation feature until a patch is available. Avoid using the password and password confirmation variables in the affected API endpoint until the issue is resolved.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-29534

Affected Products

Misp