Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-35502 app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:inde… Misp Patch available Fix from $2,3002021-06-25 HIGH 7.5 CVE-2021-31780 In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an ob… Misp Patch available Fix from $1,9502021-04-23 MEDIUM 5.5 CVE-2021-27904 An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes pr… Misp after 2.4.139 Fix from $1,6002021-03-02 MEDIUM 6.1 CVE-2020-24085 A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a l… Misp Patch available Fix from $1,6002021-01-26 CRITICAL 9.1 CVE-2021-25323 The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changin… Misp Patch available Fix from $2,3002021-01-19 MEDIUM 6.1 CVE-2021-25324 MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp. Misp Patch available Fix from $1,6002021-01-19 MEDIUM 6.1 CVE-2021-25325 MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs. Misp Patch available Fix from $1,6002021-01-19 MEDIUM 6.1 CVE-2021-3184 MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button. Misp Patch available Fix from $1,6002021-01-19 MEDIUM 6.1 CVE-2020-29572 app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field. Misp Patch available Fix from $1,6002020-12-06 CRITICAL 9.8 CVE-2020-29006 MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php. Misp 2.4.135+ Fix from $2,3002020-11-24 MEDIUM 6.1 CVE-2020-28947 In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled. Misp Patch available Fix from $1,6002020-11-19 HIGH 7.5 CVE-2020-28043 MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL. Misp after 2.4.133 Fix from $1,9502020-11-02 HIGH 7.5 CVE-2020-25766 An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the log… Misp 2.4.132+ Fix from $1,9502020-09-18 HIGH 8.8 CVE-2020-15711 In MISP before 2.4.129, setting a favourite homepage was not CSRF protected. Misp 2.4.129+ Fix from $1,9502020-07-14 CRITICAL 9.8 CVE-2020-15411 An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader. Misp Patch available Fix from $2,3002020-06-30 HIGH 7.5 CVE-2020-14969 app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, reveal… Misp Patch available Fix from $1,9502020-06-22 MEDIUM 6.1 CVE-2020-13153 app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view. Misp 2.4.126+ Fix from $1,6002020-05-18 MEDIUM 6.1 CVE-2020-10246 MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp. Misp Patch available Fix from $1,6002020-03-09 MEDIUM 6.1 CVE-2020-10247 MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp. Misp Patch available Fix from $1,6002020-03-09 HIGH 8.1 CVE-2020-8892 An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests. Misp 2.4.121+ Fix from $1,9502020-02-12 HIGH 7.5 CVE-2020-8893 An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp. Misp 2.4.121+ Fix from $1,9502020-02-12 MEDIUM 6.5 CVE-2020-8894 An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thr… Misp 2.4.121+ Fix from $1,6002020-02-12 MEDIUM 5.9 CVE-2020-8890 An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the datab… Misp 2.4.121+ Fix from $1,6002020-02-12 MEDIUM 5.9 CVE-2020-8891 An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests. Misp 2.4.121+ Fix from $1,6002020-02-12 MEDIUM 5.3 CVE-2019-19379 In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data. Misp Patch available Fix from $1,6002019-11-28 MEDIUM 6.5 CVE-2019-16202 MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLogge… Misp 2.4.115+ Fix from $1,6002019-09-10 MEDIUM 6.1 CVE-2019-14286 In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view.… Misp Patch available Fix from $1,6002019-07-27 HIGH 7.2 CVE-2019-12868EPSS 6% app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-… Misp Patch available Fix from $1,9502019-06-18 MEDIUM 6.6 CVE-2019-12794 An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability t… Misp Patch available Fix from $1,6002019-06-11 MEDIUM 6.1 CVE-2019-11812 A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion inter… Misp 2.4.107+ Fix from $1,6002019-05-08