CVE-2019-12868: High severity Misp Misp vulnerability
Published Jun 17, 2019
·Updated
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP fileexists function is used with user-controlled entries, and phar:// URLs trigger deserialization.
Affected Software
2 affected components
Misp Misp=2.4.109
Misp-project Misp=2.4.109
Remediation
Event History
Jun 17, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jun 18, 2019
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-12868.
2
What is the severity rating of CVE-2019-12868?
The severity rating of CVE-2019-12868 is high, with a severity value of 7.2.
3
How does CVE-2019-12868 allow remote command execution?
CVE-2019-12868 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.
4
What is the affected software of CVE-2019-12868?
The affected software of CVE-2019-12868 is MISP 2.4.109.
5
How can I fix CVE-2019-12868?
To fix CVE-2019-12868, it is recommended to update to a version of MISP that has the fix, such as version 2.4.110 or later.