Misp-project

Misp

141 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 07.09.2026 13:03:27
  • Zuletzt bearbeitet 14.09.2026 07:17:23

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value wit...

  • EPSS 0.24%
  • Veröffentlicht 07.09.2026 12:59:43
  • Zuletzt bearbeitet 09.09.2026 15:23:58

Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorized to view the object the reference belongs to. Th...

  • EPSS 0.22%
  • Veröffentlicht 07.09.2026 12:39:20
  • Zuletzt bearbeitet 09.09.2026 15:24:22

Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users. As a result, authent...

  • EPSS 0.26%
  • Veröffentlicht 07.09.2026 12:35:10
  • Zuletzt bearbeitet 09.09.2026 15:24:29

Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL safe if it appeared relative or ...

  • EPSS 0.33%
  • Veröffentlicht 07.09.2026 12:31:35
  • Zuletzt bearbeitet 09.09.2026 15:25:49

Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destinati...

  • EPSS 0.21%
  • Veröffentlicht 07.09.2026 12:22:52
  • Zuletzt bearbeitet 14.09.2026 07:17:23

Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fi...

  • EPSS 0.21%
  • Veröffentlicht 07.09.2026 12:17:43
  • Zuletzt bearbeitet 09.09.2026 15:26:08

Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, the same auth...

  • EPSS 0.21%
  • Veröffentlicht 07.09.2026 12:11:18
  • Zuletzt bearbeitet 09.09.2026 15:26:17

Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive ...

  • EPSS 0.33%
  • Veröffentlicht 07.09.2026 09:59:34
  • Zuletzt bearbeitet 09.09.2026 15:26:26

Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin with / but resolve to an exter...

  • EPSS 0.29%
  • Veröffentlicht 07.09.2026 09:30:58
  • Zuletzt bearbeitet 09.09.2026 15:26:35

Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-manage...