CVE-2024-58130: XSS
Published Mar 28, 2025
·Updated
In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.
Affected Software
2 affected components
Misp Misp<2.4.193
Misp-project Misp<2.4.193
Remediation
Event History
Mar 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-58130?
CVE-2024-58130 has a moderate severity due to the lack of sanitization for non-JSON responses in MISP.
2
How do I fix CVE-2024-58130?
To mitigate CVE-2024-58130, upgrade your MISP installation to version 2.4.193 or later.
3
What types of software are affected by CVE-2024-58130?
CVE-2024-58130 affects MISP versions prior to 2.4.193.
4
What impact does CVE-2024-58130 have on my application?
CVE-2024-58130 may lead to potential security vulnerabilities due to improper handling of non-JSON responses.
5
Is there a workaround for CVE-2024-58130?
There are no known workarounds for CVE-2024-58130; the recommended action is to update MISP to the patched version.