CVE-2022-48329: Critical severity Misp Misp vulnerability
Published Feb 20, 2023
·Updated
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
Affected Software
2 affected components
Misp Misp<2.4.166
Misp-project Misp<2.4.166
Remediation
Event History
Feb 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-48329?
CVE-2022-48329 is a vulnerability in MISP that allows users to use the order parameter in an unsafe manner.
2
What is the severity of CVE-2022-48329?
CVE-2022-48329 has a severity rating of critical, with a score of 9.8.
3
Which software versions are affected by CVE-2022-48329?
MISP versions up to and excluding 2.4.166 are affected by CVE-2022-48329.
4
How can I fix CVE-2022-48329?
To fix CVE-2022-48329, update MISP to version 2.4.166 or later.
5
Is there any additional information about CVE-2022-48329?
You can find more information about CVE-2022-48329 in the provided references: [link1], [link2], [link3].