First published: Tue Feb 11 2020(Updated: )
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.121 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-8890.
The severity of CVE-2020-8890 is medium with a severity score of 5.9.
The affected software for CVE-2020-8890 is MISP version up to 2.4.121.
CVE-2020-8890 is a vulnerability in MISP versions before 2.4.121 that mishandles time skew, leading to a failure to block a brute-force series of invalid requests.
To fix CVE-2020-8890, users should update to MISP version 2.4.121 or later.