CVE-2024-25675: Critical severity Misp-project Misp vulnerability
Published Feb 9, 2024
·Updated
An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.
Affected Software
1 affected component
Misp-project Misp<2.4.184
Remediation
Event History
Feb 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25675?
The severity of CVE-2024-25675 is moderate as it allows unauthorized export generation without POST requests.
2
How do I fix CVE-2024-25675?
To fix CVE-2024-25675, update MISP to version 2.4.184 or later.
3
What versions of MISP are affected by CVE-2024-25675?
MISP versions prior to 2.4.184 are affected by CVE-2024-25675.
4
What type of vulnerability is CVE-2024-25675?
CVE-2024-25675 is a security vulnerability related to improper validation in export functionality.
5
Can CVE-2024-25675 lead to data leaks?
Yes, CVE-2024-25675 can potentially lead to unauthorized access to sensitive information through export operations.