CVE-2022-48328: Critical severity Misp Misp vulnerability
Published Feb 20, 2023
·Updated
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles orderedurlparams and additionaldelimiters.
Affected Software
2 affected components
Misp Misp<2.4.167
Misp-project Misp<2.4.167
Remediation
Event History
Feb 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-48328?
The severity of CVE-2022-48328 is critical with a score of 9.8.
2
What is the affected software of CVE-2022-48328?
The affected software of CVE-2022-48328 is MISP before version 2.4.167.
3
How does CVE-2022-48328 affect MISP?
CVE-2022-48328 affects MISP by mishandling ordered_url_params and additional_delimiters in the app/Controller/Component/IndexFilterComponent.php file.
4
Are there any fixes or patches available for CVE-2022-48328?
Yes, fixes and patches for CVE-2022-48328 are available in the following commits: [Commit 1](https://github.com/MISP/MISP/commit/1edbc2569989f844799261a5f90edfa433d7dbcc) and [Commit 2](https://github.com/MISP/MISP/commit/206f540f0275af2dd2a86275abc199df41e72a21).
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-48328?
The Common Weakness Enumeration (CWE) ID for CVE-2022-48328 is CWE-755.