CVE-2022-42724: Medium severity Misp-project Malware Information Sharing Platform vulnerability
Published Oct 10, 2022
·Updated
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).
Affected Software
2 affected components
Misp-project Malware Information Sharing Platform<2.4.164
Misp-project Misp<2.4.164
Remediation
Event History
Oct 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-42724.
2
What is the severity of CVE-2022-42724?
The severity of CVE-2022-42724 is medium.
3
How can an attacker exploit CVE-2022-42724?
CVE-2022-42724 allows attackers to discover role names that should only be known by the site admin.
4
Which version of MISP is affected by CVE-2022-42724?
MISP versions up to and excluding 2.4.164 are affected by CVE-2022-42724.
5
Is there a patch available for CVE-2022-42724?
Yes, a patch is available for CVE-2022-42724. Please refer to the following reference for more information: [GitHub Commit](https://github.com/MISP/MISP/commit/934b9cd4fc6d6378ad349ea630ad9f1319ac82f5).