First published: Mon Feb 20 2023(Updated: )
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp Misp | <2.4.166 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48329 is a vulnerability in MISP that allows users to use the order parameter in an unsafe manner.
CVE-2022-48329 has a severity rating of critical, with a score of 9.8.
MISP versions up to and excluding 2.4.166 are affected by CVE-2022-48329.
To fix CVE-2022-48329, update MISP to version 2.4.166 or later.
You can find more information about CVE-2022-48329 in the provided references: [link1], [link2], [link3].