CVE-2020-29006: Critical severity Misp Misp vulnerability
Published Nov 24, 2020
·Updated
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
Affected Software
2 affected components
Misp Misp<2.4.135
Misp-project Misp<2.4.135
Remediation
Event History
Nov 24, 2020
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this MISP vulnerability?
The vulnerability ID for this MISP vulnerability is CVE-2020-29006.
2
What is the severity of CVE-2020-29006?
The severity of CVE-2020-29006 is critical.
3
What is the affected software for CVE-2020-29006?
The affected software for CVE-2020-29006 is MISP version up to and excluding 2.4.135.
4
What is the CWE ID for CVE-2020-29006?
The CWE ID for CVE-2020-29006 is 862.
5
How can I fix CVE-2020-29006?
To fix CVE-2020-29006, you need to update to MISP version 2.4.135 or newer.