CVE-2020-29572: XSS
Published Dec 5, 2020
·Updated
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
Affected Software
2 affected components
Misp Misp=2.4.135
Misp-project Misp=2.4.135
Remediation
Event History
Dec 5, 2020
CVE Published
via MITRE·11:02 PM
Data Sourced
via MITRE·11:02 PM
Description
Dec 6, 2020
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-29572?
CVE-2020-29572 is a vulnerability in MISP 2.4.135 that allows cross-site scripting (XSS) attacks through the authkey comment field.
2
What is the severity of CVE-2020-29572?
The severity of CVE-2020-29572 is medium, with a CVSS score of 6.1.
3
How does CVE-2020-29572 affect MISP?
CVE-2020-29572 affects MISP version 2.4.135.
4
How can I fix CVE-2020-29572 in MISP?
To fix CVE-2020-29572, update MISP to a version that includes the fix, such as 2.4.136 or later.
5
Is there any additional reference for CVE-2020-29572?
Yes, you can find more information about CVE-2020-29572 in the official GitHub commit: https://github.com/MISP/MISP/commit/0bfc0bf38a7758b27c5c446fec5e3b905e5a54ab