First published: Mon Jun 22 2020(Updated: )
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | =2.4.127 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14969 is a vulnerability in MISP version 2.4.127 that allows unauthorized access to metadata about correlating but unreachable attributes.
CVE-2020-14969 has a severity rating of 7.5 (high).
CVE-2020-14969 affects MISP version 2.4.127.
To fix CVE-2020-14969, update MISP to a version that includes the commit 609bfbd450c933d21c50c9f0161d633c43413eb6.
CVE-2020-14969 is associated with CWE-ID 862.