First published: Sat Nov 25 2017(Updated: )
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MISP | =2.4.82 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16946 is considered a medium severity vulnerability due to its potential impact on the confidentiality of hashed passwords.
To fix CVE-2017-16946, you should upgrade MISP to a version later than 2.4.82 where the issue has been resolved.
CVE-2017-16946 affects installations of MISP version 2.4.82 specifically.
The main risk of CVE-2017-16946 is that an admin could inadvertently expose hashed passwords through audit logs.
CVE-2017-16946 is not considered easy to exploit as it requires access to the audit logs by an administrator.