CVE-2022-29532: XSS
Published Apr 20, 2022
·Updated
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.
Affected Software
2 affected components
Misp Misp<2.4.158
Misp-project Misp<2.4.158
Remediation
Event History
Apr 20, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-29532?
CVE-2022-29532 is a vulnerability in MISP version 2.4.158 and below that allows for a stored XSS attack if an administrator clicks on a javascript: URL in the URL field.
2
How severe is CVE-2022-29532?
CVE-2022-29532 has a severity rating of medium with a CVSS score of 4.8.
3
How does CVE-2022-29532 affect MISP?
CVE-2022-29532 affects MISP versions before 2.4.158 and can be exploited to perform a stored XSS attack.
4
Is there a fix available for CVE-2022-29532?
Yes, the fix for CVE-2022-29532 is included in MISP version 2.4.158.
5
How can I protect my MISP installation from CVE-2022-29532?
To protect your MISP installation from CVE-2022-29532, make sure to update to version 2.4.158 or later.