Misp

Misp

45 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 22.06.2026 12:39:31
  • Zuletzt bearbeitet 23.06.2026 14:16:17

MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration ...

  • EPSS 0.31%
  • Veröffentlicht 22.06.2026 12:31:40
  • Zuletzt bearbeitet 23.06.2026 16:17:05

MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could ...

  • EPSS 0.3%
  • Veröffentlicht 22.06.2026 12:25:00
  • Zuletzt bearbeitet 26.06.2026 20:33:09

The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the P...

  • EPSS 0.31%
  • Veröffentlicht 22.06.2026 12:17:17
  • Zuletzt bearbeitet 23.06.2026 15:16:39

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated u...

  • EPSS 0.23%
  • Veröffentlicht 22.06.2026 11:56:26
  • Zuletzt bearbeitet 23.06.2026 15:16:39

MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authorization for eac...

  • EPSS 0.36%
  • Veröffentlicht 22.06.2026 11:43:02
  • Zuletzt bearbeitet 22.06.2026 18:16:49

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and rela...

  • EPSS 0.22%
  • Veröffentlicht 12.06.2026 21:08:15
  • Zuletzt bearbeitet 15.06.2026 20:46:57

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or vi...

  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 20:55:53
  • Zuletzt bearbeitet 15.06.2026 20:46:57

A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data and set an event’s sharing_group_id to a sharing group they were not authorized to use. When distrib...

  • EPSS 0.25%
  • Veröffentlicht 12.06.2026 20:48:18
  • Zuletzt bearbeitet 15.06.2026 20:46:57

An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit request, the user dropdown was populated using the attacker-controlled AuthKey.user_id value from the submitt...

  • EPSS 0.26%
  • Veröffentlicht 12.06.2026 20:36:09
  • Zuletzt bearbeitet 15.06.2026 20:46:57

MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScript handler using HTML escaping inside a single-quoted JavaScript string. Because browsers HTML-decode ...