CVE-2020-28043: SSRF
Published Nov 1, 2020
·Updated
MISP through 2.4.133 allows SSRF in the REST client via the usefullpath parameter with an arbitrary URL.
Affected Software
2 affected components
Misp Misp<=2.4.133
Misp-project Misp<=2.4.133
Remediation
Event History
Nov 1, 2020
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
Description
Nov 2, 2020
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-28043.
2
What is the severity of CVE-2020-28043?
The severity of CVE-2020-28043 is high (7.5).
3
How does CVE-2020-28043 allow SSRF?
CVE-2020-28043 allows SSRF through the use_full_path parameter with an arbitrary URL.
4
Which software versions are affected by CVE-2020-28043?
Versions up to and including 2.4.133 of MISP are affected by CVE-2020-28043.
5
Is there a fix for CVE-2020-28043?
Yes, a fix for CVE-2020-28043 is available. Please refer to the provided reference for more information.