First published: Fri Feb 09 2024(Updated: )
An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MISP | <2.4.184 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-25675 is moderate as it allows unauthorized export generation without POST requests.
To fix CVE-2024-25675, update MISP to version 2.4.184 or later.
MISP versions prior to 2.4.184 are affected by CVE-2024-25675.
CVE-2024-25675 is a security vulnerability related to improper validation in export functionality.
Yes, CVE-2024-25675 can potentially lead to unauthorized access to sensitive information through export operations.