CVE-2019-9482

MEDIUM

MISP 2.4.102 - Authenticated Missing Authorization for Sighting Visibility

Title source: llm
STIX 2.1

Description

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0074
EPSS Percentile 51.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-862
Status published
Products (2)
misp/misp 2.4.102
misp-project/misp 2.4.102
Published Mar 01, 2019
Tracked Since Feb 18, 2026