MISP
cpe:2.3:a:misp:misp:*:*:*:*:*:*:*
An authorization bypass vulnerability has been identified in MISP's EventsController import module. This issue allows authenticated users or read-only API keys with event view access to persist data to events they are not authorized to modify. The vulnerability arises because the import module does not verify event modification rights before saving output from modules that return results in the 'misp_standard' format. As a result, a view-only user could inject or alter event data, compromising the integrity of MISP event content. The vulnerability has been addressed by enforcing the same modification rights check that is used in related module result handling paths, ensuring that only authorized users can make changes to event data.
Exploitation of this vulnerability could lead to unauthorized modification of event data by users who should only have view access, thereby undermining the integrity of the information within MISP events.
Users should update to the latest version of MISP, where this vulnerability has been fixed. Instructions for updating can be found in the MISP documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.