CVE-2021-25323: Critical severity Misp Misp vulnerability
The default setting of MISP 2.4.136 did not enable the requirements (aka requirepasswordconfirmation) to provide the previous password when changing a password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable the require_password_confirmation setting (set to true) so users must provide their previous password when changing their password.
MISP (2.4.136) require_password_confirmation = true
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue with MISP?
The vulnerability ID for this issue with MISP is CVE-2021-25323.
What is the severity of CVE-2021-25323?
The severity of CVE-2021-25323 is critical with a CVSS score of 9.1.
What is the affected software version of CVE-2021-25323?
The affected software version of CVE-2021-25323 is MISP 2.4.136.
What is the description of CVE-2021-25323?
CVE-2021-25323 is a vulnerability in MISP 2.4.136 that does not enable the requirements to provide the previous password when changing a password.
Is there a fix or patch available for CVE-2021-25323?
Yes, a fix has been implemented in MISP 2.4.136. Users are advised to update to the latest version of MISP to mitigate this vulnerability.