CVE-2019-9482

MEDIUM

MISP 2.4.102 - Info Disclosure

Title source: llm
STIX 2.1

Description

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0027
EPSS Percentile 50.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-862
Status published
Products (1)
misp/misp 2.4.102
Published Mar 01, 2019
Tracked Since Feb 18, 2026