CVE-2021-35502: Critical severity Misp Misp vulnerability
Published Jun 25, 2021
·Updated
app/View/Elements/genericElements/IndexTable/Fields/genericfield.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.
Affected Software
2 affected components
Misp Misp=2.4.144
Misp-project Misp=2.4.144
Remediation
Event History
Jun 25, 2021
CVE Published
via MITRE·08:49 PM
Data Sourced
via MITRE·08:49 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-35502?
The severity of CVE-2021-35502 is critical, with a CVSS score of 9.8.
2
What is the affected software version of CVE-2021-35502?
CVE-2021-35502 affects MISP version 2.4.144.
3
How does CVE-2021-35502 impact MISP?
CVE-2021-35502 allows the execution of arbitrary code or commands, which can lead to full system compromise.
4
Is there a fix available for CVE-2021-35502?
Yes, a fix for CVE-2021-35502 is available in the commit 2fde6476dc3173affc61874ba2adb35400a8fda5 on the MISP GitHub repository.
5
Where can I find more information about CVE-2021-35502?
You can find more information about CVE-2021-35502 at the following link: [GitHub commit](https://github.com/MISP/MISP/commit/2fde6476dc3173affc61874ba2adb35400a8fda5)