CVE-2020-15711: CSRF
Published Jul 14, 2020
·Updated
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
Affected Software
2 affected components
Misp Misp<2.4.129
Misp-project Misp<2.4.129
Remediation
Patch Available
Event History
Jul 14, 2020
CVE Published
via MITRE·12:05 PM
Data Sourced
via MITRE·12:05 PM
Description
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-15711?
CVE-2020-15711 is a vulnerability in MISP before 2.4.129 where setting a favorite homepage was not CSRF protected.
2
What is the severity of CVE-2020-15711?
The severity of CVE-2020-15711 is high with a CVSS score of 8.8.
3
What software versions are affected by CVE-2020-15711?
MISP versions up to and excluding 2.4.129 are affected by CVE-2020-15711.
4
How can I fix CVE-2020-15711?
To fix CVE-2020-15711, you should upgrade MISP to version 2.4.129 or later.
5
Where can I find more information about CVE-2020-15711?
You can find more information about CVE-2020-15711 on the GitHub commit page: https://github.com/MISP/MISP/commit/bf4610c947c7dc372c4078f363d2dff6ae0703a8