CVE-2021-27904: Medium severity Misp Misp vulnerability
Published Mar 2, 2021
·Updated
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.
Affected Software
2 affected components
Misp Misp<=2.4.139
Misp-project Misp<=2.4.139
Remediation
Event History
Mar 2, 2021
CVE Published
via MITRE·06:58 AM
Data Sourced
via MITRE·06:58 AM
Description
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-27904.
2
What is the severity of CVE-2021-27904?
The severity of CVE-2021-27904 is medium with a CVSS score of 5.5.
3
What is affected by CVE-2021-27904?
MISP version 2.4.139 is affected by CVE-2021-27904.
4
What is the description of CVE-2021-27904?
CVE-2021-27904 is an issue in the implementation of Sharing Groups in MISP 2.4.139 where the "all org" flag can provide unintended actors with view access.
5
Is there a fix available for CVE-2021-27904?
Yes, a fix for CVE-2021-27904 is available. Please refer to the provided reference link for more information.