CVE-2020-8890

MEDIUM

MISP <2.4.121 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.

References (3)

Core 3

Scores

CVSS v3 5.9
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-367
Status published
Products (1)
misp/misp < 2.4.121
Published Feb 12, 2020
Tracked Since Feb 18, 2026