First published: Tue Feb 11 2020(Updated: )
An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.121 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8894 is a vulnerability in MISP version 2.4.121 and earlier that mishandles ACLs for discussion threads.
CVE-2020-8894 has a severity keyword of 'medium' and a severity value of 6.5.
MISP versions up to and excluding 2.4.121 are affected by CVE-2020-8894.
To fix CVE-2020-8894, update your MISP installation to version 2.4.121 or later.
Yes, you can refer to the following links for more information on CVE-2020-8894: [Link 1](https://github.com/MISP/MISP/commit/9400b8bc8699435d84508e598aca98a31affd77c), [Link 2](https://github.com/MISP/MISP/compare/v2.4.120...v2.4.121), [Link 3](https://zigrin.com/advisories/misp-mishandling-of-discussion-threads-acls/).