CVE-2024-29858: Critical severity Misp Misp vulnerability
Published Mar 21, 2024
·Updated
In MISP before 2.4.187, uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
Affected Software
2 affected components
Misp Misp<2.4.187
Misp-project Misp<2.4.187
Remediation
Event History
Mar 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29858?
CVE-2024-29858 has a medium severity rating due to its potential for improper file uploads.
2
How do I fix CVE-2024-29858?
To fix CVE-2024-29858, upgrade MISP to version 2.4.187 or later.
3
What is the vulnerable functionality in CVE-2024-29858?
The vulnerability in CVE-2024-29858 affects the __uploadLogo method in OrganisationsController.php.
4
Which versions of MISP are affected by CVE-2024-29858?
MISP versions prior to 2.4.187 are impacted by CVE-2024-29858.
5
Is it safe to upload logos in MISP versions before 2.4.187 due to CVE-2024-29858?
No, it is not safe to upload logos in MISP versions before 2.4.187 because of the lack of validation in the upload process.