Misp

Misp

147 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 03.09.2026 15:22:59
  • Zuletzt bearbeitet 11.09.2026 14:15:51

A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating subm...

  • EPSS 0.2%
  • Veröffentlicht 03.09.2026 15:13:00
  • Zuletzt bearbeitet 11.09.2026 14:14:30

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to ...

  • EPSS 0.31%
  • Veröffentlicht 03.09.2026 14:48:41
  • Zuletzt bearbeitet 10.09.2026 19:37:59

A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the configuration was saved. As a result, an a...

  • EPSS 0.27%
  • Veröffentlicht 03.09.2026 14:42:02
  • Zuletzt bearbeitet 10.09.2026 19:38:21

MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the query-builder rules without HTML escaping befor...

  • EPSS 0.23%
  • Veröffentlicht 03.09.2026 14:35:17
  • Zuletzt bearbeitet 10.09.2026 19:39:34

MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other access-control restrictions assoc...

  • EPSS 0.09%
  • Veröffentlicht 03.09.2026 14:16:59
  • Zuletzt bearbeitet 10.09.2026 19:40:05

MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value effectively disabled TLS peer verif...

  • EPSS 0.48%
  • Veröffentlicht 03.09.2026 13:59:35
  • Zuletzt bearbeitet 10.09.2026 19:42:07

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAu...

  • EPSS 0.28%
  • Veröffentlicht 24.08.2026 13:26:56
  • Zuletzt bearbeitet 26.08.2026 16:49:18

RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual post is marked private but does n...

  • EPSS 0.49%
  • Veröffentlicht 28.07.2026 14:30:22
  • Zuletzt bearbeitet 30.07.2026 16:55:34

MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example Apache’s Redirect directive appends any portion of the requested pat...

  • EPSS 0.24%
  • Veröffentlicht 09.07.2026 15:06:00
  • Zuletzt bearbeitet 09.07.2026 17:17:04

An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to add attributes to submit a sharing_group_id without triggering the corresponding sharing group authorization check, as long as the ...