First published: Tue Nov 24 2020(Updated: )
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.135 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this MISP vulnerability is CVE-2020-29006.
The severity of CVE-2020-29006 is critical.
The affected software for CVE-2020-29006 is MISP version up to and excluding 2.4.135.
The CWE ID for CVE-2020-29006 is 862.
To fix CVE-2020-29006, you need to update to MISP version 2.4.135 or newer.