CVE-2020-14969: High severity Misp Misp vulnerability
Published Jun 22, 2020
·Updated
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
Affected Software
2 affected components
Misp Misp=2.4.127
Misp-project Misp=2.4.127
Remediation
Event History
Jun 22, 2020
CVE Published
via MITRE·11:48 AM
Data Sourced
via MITRE·11:48 AM
Description
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-14969?
CVE-2020-14969 is a vulnerability in MISP version 2.4.127 that allows unauthorized access to metadata about correlating but unreachable attributes.
2
How severe is CVE-2020-14969?
CVE-2020-14969 has a severity rating of 7.5 (high).
3
What is the affected software version of CVE-2020-14969?
CVE-2020-14969 affects MISP version 2.4.127.
4
How can I fix CVE-2020-14969?
To fix CVE-2020-14969, update MISP to a version that includes the commit 609bfbd450c933d21c50c9f0161d633c43413eb6.
5
What is the CWE-ID of CVE-2020-14969?
CVE-2020-14969 is associated with CWE-ID 862.