First published: Fri Feb 09 2024(Updated: )
An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MISP | <2.4.184 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25674 has a medium severity rating due to the potential for security risks related to insecure file uploads.
To fix CVE-2024-25674, upgrade MISP to version 2.4.184 or later to ensure secure organisation logo uploads.
Under CVE-2024-25674, any file uploaded as an organisation logo is vulnerable due to inadequate checks on file extensions and MIME types.
CVE-2024-25674 affects MISP versions earlier than 2.4.184.
Yes, CVE-2024-25674 presents a constant threat to MISP installations below version 2.4.184 if the vulnerability is not remediated.