First published: Sun Nov 01 2020(Updated: )
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <=2.4.133 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-28043.
The severity of CVE-2020-28043 is high (7.5).
CVE-2020-28043 allows SSRF through the use_full_path parameter with an arbitrary URL.
Versions up to and including 2.4.133 of MISP are affected by CVE-2020-28043.
Yes, a fix for CVE-2020-28043 is available. Please refer to the provided reference for more information.