MISP
cpe:2.3:a:misp:misp:*:*:*:*:*:*:*
A log flooding vulnerability has been identified in MISP (Malware Information Sharing Platform) versions prior to 2.5.38. The issue arises in the Content Security Policy (CSP) report endpoint, which was supposed to limit CSP reports to 1 KB but mistakenly allowed reports of up to 1 MB before truncation. In deployments where this endpoint is accessible to untrusted clients, attackers could exploit this flaw to generate excessive log volume, leading to resource exhaustion or log flooding.
Exploitation of this vulnerability could result in excessive log generation, causing resource exhaustion or log flooding on the affected system.
Users can upgrade to MISP version 2.5.38 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.