First published: Tue Feb 11 2020(Updated: )
An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.121 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8891 is a vulnerability discovered in MISP before version 2.4.121 that allows for a brute-force attack by not canonicalizing usernames when trying to block a series of invalid requests.
The severity of CVE-2020-8891 is medium with a severity value of 5.9.
The affected software for CVE-2020-8891 is MISP version up to exclusive 2.4.121.
To fix CVE-2020-8891, update MISP to version 2.4.121 or later.
You can find more information about CVE-2020-8891 in the provided references: [GitHub Commit 934c82819237b4edf1da64587b72a87bec5dd520](https://github.com/MISP/MISP/commit/934c82819237b4edf1da64587b72a87bec5dd520), [GitHub Commit c1a0b3b2809b21b4df8c1efbc803aff700e262c3](https://github.com/MISP/MISP/commit/c1a0b3b2809b21b4df8c1efbc803aff700e262c3), [GitHub Comparison v2.4.120...v2.4.121](https://github.com/MISP/MISP/compare/v2.4.120...v2.4.121).