CVE-2020-15412: Medium severity Misp Misp vulnerability
Published Jun 30, 2020
·Updated
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
Affected Software
2 affected components
Misp Misp=2.4.128
Misp-project Misp=2.4.128
Remediation
Event History
Jun 30, 2020
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-15412.
2
What is the severity of CVE-2020-15412?
The severity of CVE-2020-15412 is medium.
3
How does CVE-2020-15412 affect MISP?
CVE-2020-15412 affects MISP version 2.4.128.
4
What is the root cause of CVE-2020-15412?
The root cause of CVE-2020-15412 is that app/Controller/EventsController.php lacks an event ACL check before allowing a user to send an event contact form.
5
Is there a fix available for CVE-2020-15412?
Yes, a fix is available. The fix can be found in the referenced commit on GitHub.