CVE-2019-19379: Medium severity Misp Misp vulnerability
Published Nov 28, 2019
·Updated
In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.
Affected Software
2 affected components
Misp Misp=2.4.118
Misp-project Misp=2.4.118
Remediation
Event History
Nov 28, 2019
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this MISP version?
The vulnerability ID for MISP version 2.4.118 is CVE-2019-19379.
2
What is the severity of CVE-2019-19379?
The severity of CVE-2019-19379 is medium with a CVSS score of 5.3.
3
What is the affected software for CVE-2019-19379?
The affected software for CVE-2019-19379 is MISP version 2.4.118.
4
How can users bypass the intended restrictions on tagging data?
In MISP 2.4.118, users can bypass the intended restrictions on tagging data through app/Controller/TagsController.php.
5
Is there a fix or patch available for CVE-2019-19379?
Yes, a fix for CVE-2019-19379 is available in the commit e05dc512a437284f14624da23cca4a829a76aebf on GitHub.