CVE-2022-29534: High severity Misp Misp vulnerability
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-29534.
What is the severity rating of CVE-2022-29534?
CVE-2022-29534 has a severity rating of 7.5 (high).
How does this vulnerability impact MISP?
This vulnerability in MISP allows bypassing password confirmation via vectors involving an 'Accept: application/json' header.
Which version of MISP is affected by CVE-2022-29534?
MISP versions up to and excluding 2.4.158 are affected by CVE-2022-29534.
Are there any references or resources for CVE-2022-29534?
Yes, you can find references and additional information about CVE-2022-29534 in the following links: [Link 1](https://github.com/MISP/MISP/commit/01120163a6b4d905029d416e7305575df31df8af), [Link 2](https://github.com/MISP/MISP/compare/v2.4.157...v2.4.158), [Link 3](https://zigrin.com/cakephp-application-cybersecurity-research-the-impact-of-a-php-vulnerability-exploring-the-password-confirmation-bypass-in-misp/).