CVE-2024-57969: Medium severity Misp Misp vulnerability
Published Feb 14, 2025
·Updated
app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.
Affected Software
2 affected components
Misp Misp<2.4.198
Misp-project Misp<2.4.198
Remediation
Event History
Feb 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-57969?
The severity of CVE-2024-57969 is classified as medium due to the potential bypass of access control in MISP.
2
How do I fix CVE-2024-57969?
To fix CVE-2024-57969, upgrade MISP to version 2.4.198 or later.
3
What is the impact of CVE-2024-57969 on MISP?
CVE-2024-57969 allows unauthorized users to conduct GUI attribute searches, potentially exposing sensitive information.
4
Is CVE-2024-57969 exploitable remotely?
Yes, CVE-2024-57969 is exploitable remotely since it affects the web interface of MISP.
5
When was CVE-2024-57969 reported?
CVE-2024-57969 was reported in 2024 and affects versions of MISP prior to 2.4.198.