CVE-2022-29529: XSS
Published Apr 20, 2022
·Updated
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
Affected Software
2 affected components
Misp Misp<2.4.158
Misp-project Misp<2.4.158
Remediation
Event History
Apr 20, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-29529?
CVE-2022-29529 is a vulnerability discovered in MISP before version 2.4.158 that allows for stored cross-site scripting (XSS) attacks via the LinOTP login field.
2
How severe is CVE-2022-29529?
CVE-2022-29529 has a severity rating of medium with a CVSS score of 5.4.
3
Which software versions are affected by CVE-2022-29529?
CVE-2022-29529 affects MISP versions up to, but excluding, 2.4.158.
4
How can I fix CVE-2022-29529?
To fix CVE-2022-29529, it is recommended to update MISP to version 2.4.158 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-29529?
The CWE ID for CVE-2022-29529 is CWE-79, which corresponds to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').