Misp

Misp

50 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 24.08.2026 13:26:56
  • Zuletzt bearbeitet 24.08.2026 16:17:23

RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual post is marked private but does n...

  • EPSS 0.49%
  • Veröffentlicht 28.07.2026 14:30:22
  • Zuletzt bearbeitet 30.07.2026 16:55:34

MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example Apache’s Redirect directive appends any portion of the requested pat...

  • EPSS 0.24%
  • Veröffentlicht 09.07.2026 15:06:00
  • Zuletzt bearbeitet 09.07.2026 17:17:04

An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to add attributes to submit a sharing_group_id without triggering the corresponding sharing group authorization check, as long as the ...

  • EPSS 0.21%
  • Veröffentlicht 08.07.2026 13:36:53
  • Zuletzt bearbeitet 09.07.2026 16:29:14

MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not enforce the per-organisation module restriction checked by getEnabledModules(). As a result, an authenticated user from an organisat...

  • EPSS 0.22%
  • Veröffentlicht 08.07.2026 13:30:14
  • Zuletzt bearbeitet 09.07.2026 16:29:14

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_...

  • EPSS 0.3%
  • Veröffentlicht 22.06.2026 12:39:31
  • Zuletzt bearbeitet 23.06.2026 14:16:17

MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration ...

  • EPSS 0.39%
  • Veröffentlicht 22.06.2026 12:31:40
  • Zuletzt bearbeitet 23.06.2026 16:17:05

MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could ...

  • EPSS 0.26%
  • Veröffentlicht 22.06.2026 12:25:00
  • Zuletzt bearbeitet 26.06.2026 20:33:09

The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the P...

  • EPSS 0.31%
  • Veröffentlicht 22.06.2026 12:17:17
  • Zuletzt bearbeitet 23.06.2026 15:16:39

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated u...

  • EPSS 0.33%
  • Veröffentlicht 22.06.2026 11:56:26
  • Zuletzt bearbeitet 23.06.2026 15:16:39

MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authorization for eac...