First published: Fri Jan 20 2023(Updated: )
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Misp-project Misp | =2.4.167 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24028 is critical.
CVE-2023-24028 affects MISP version 2.4.167.
CVE-2023-24028 is a vulnerability in MISP 2.4.167 that has incorrect access control for the decaying import function.
To fix CVE-2023-24028, it is recommended to update MISP to a version that includes the fix, such as version 2.4.168 or later.
You can find more information about CVE-2023-24028 at the following link: https://github.com/MISP/MISP/commit/93bf15d3bd703a32ebfe86cb6c1c9b735cf23e30