CVE-2021-41326: Critical severity Misp Misp vulnerability
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shellexec call.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41326?
The severity of CVE-2021-41326 is critical with a CVSS score of 9.8.
How does CVE-2021-41326 affect MISP?
CVE-2021-41326 affects MISP versions before 2.4.148.
What is the vulnerability in MISP?
The vulnerability in MISP is a command injection vulnerability in the app/Lib/Export/OpendataExport.php file.
How can I fix CVE-2021-41326 in MISP?
To fix CVE-2021-41326 in MISP, you should update to version 2.4.148 or later.
Where can I find more information about CVE-2021-41326?
You can find more information about CVE-2021-41326 in the references provided: [GitHub Commit](https://github.com/MISP/MISP/commit/e36f73947e741bc97320f0c42199acd1a94c7051), [GitHub Comparison](https://github.com/MISP/MISP/compare/v2.4.147...v2.4.148), [Advisory](https://zigrin.com/advisories/misp-command-injection-vulnerability-in-opendata-export/).