CVE-2024-25674: Malicious File Upload
Published Feb 9, 2024
·Updated
An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.
Affected Software
1 affected component
Misp-project Misp<2.4.184
Remediation
Event History
Feb 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 2, 56089
Event
via FIRST·11:35 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-25674?
CVE-2024-25674 has a medium severity rating due to the potential for security risks related to insecure file uploads.
2
How do I fix CVE-2024-25674?
To fix CVE-2024-25674, upgrade MISP to version 2.4.184 or later to ensure secure organisation logo uploads.
3
What types of files are vulnerable in CVE-2024-25674?
Under CVE-2024-25674, any file uploaded as an organisation logo is vulnerable due to inadequate checks on file extensions and MIME types.
4
Which versions of MISP are affected by CVE-2024-25674?
CVE-2024-25674 affects MISP versions earlier than 2.4.184.
5
Is CVE-2024-25674 constant threat to MISP installations?
Yes, CVE-2024-25674 presents a constant threat to MISP installations below version 2.4.184 if the vulnerability is not remediated.