MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115)" message.
References
Link | Resource |
---|---|
https://github.com/MISP/MISP/commit/75acd63c46506ad404764c3a3de7d4ca11d0560f | Patch Third Party Advisory |
https://github.com/MISP/MISP/compare/v2.4.114...v2.4.115 | Patch Third Party Advisory |
https://excellium-services.com/cert-xlm-advisory/cve-2019-16202/ | Third Party Advisory |
Configurations
Information
Published : 2019-09-10 07:15
Updated : 2019-09-11 11:34
NVD link : CVE-2019-16202
Mitre link : CVE-2019-16202
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
misp
- misp