Misp

Misp

147 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 10.09.2026 13:41:51
  • Zuletzt bearbeitet 10.09.2026 17:17:09

MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the convert_markdown...

  • EPSS 0.26%
  • Veröffentlicht 10.09.2026 13:04:03
  • Zuletzt bearbeitet 10.09.2026 18:18:15

Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value in...

  • EPSS 0.34%
  • Veröffentlicht 07.09.2026 13:03:27
  • Zuletzt bearbeitet 14.09.2026 07:17:23

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value wit...

  • EPSS 0.24%
  • Veröffentlicht 07.09.2026 12:59:43
  • Zuletzt bearbeitet 09.09.2026 15:23:58

Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorized to view the object the reference belongs to. Th...

  • EPSS 0.22%
  • Veröffentlicht 07.09.2026 12:39:20
  • Zuletzt bearbeitet 09.09.2026 15:24:22

Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users. As a result, authent...

  • EPSS 0.26%
  • Veröffentlicht 07.09.2026 12:35:10
  • Zuletzt bearbeitet 09.09.2026 15:24:29

Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL safe if it appeared relative or ...

  • EPSS 0.33%
  • Veröffentlicht 07.09.2026 12:31:35
  • Zuletzt bearbeitet 09.09.2026 15:25:49

Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destinati...

  • EPSS 0.21%
  • Veröffentlicht 07.09.2026 12:22:52
  • Zuletzt bearbeitet 14.09.2026 07:17:23

Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fi...

  • EPSS 0.21%
  • Veröffentlicht 07.09.2026 12:17:43
  • Zuletzt bearbeitet 09.09.2026 15:26:08

Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, the same auth...

  • EPSS 0.21%
  • Veröffentlicht 07.09.2026 12:11:18
  • Zuletzt bearbeitet 09.09.2026 15:26:17

Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive ...