MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115)" message.
References
Link | Resource |
---|---|
https://excellium-services.com/cert-xlm-advisory/cve-2019-16202/ | Third Party Advisory |
https://github.com/MISP/MISP/commit/75acd63c46506ad404764c3a3de7d4ca11d0560f | Patch Third Party Advisory |
https://github.com/MISP/MISP/compare/v2.4.114...v2.4.115 | Patch Third Party Advisory |
https://excellium-services.com/cert-xlm-advisory/cve-2019-16202/ | Third Party Advisory |
https://github.com/MISP/MISP/commit/75acd63c46506ad404764c3a3de7d4ca11d0560f | Patch Third Party Advisory |
https://github.com/MISP/MISP/compare/v2.4.114...v2.4.115 | Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 04:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://excellium-services.com/cert-xlm-advisory/cve-2019-16202/ - Third Party Advisory | |
References | () https://github.com/MISP/MISP/commit/75acd63c46506ad404764c3a3de7d4ca11d0560f - Patch, Third Party Advisory | |
References | () https://github.com/MISP/MISP/compare/v2.4.114...v2.4.115 - Patch, Third Party Advisory |
Information
Published : 2019-09-10 14:15
Updated : 2024-11-21 04:30
NVD link : CVE-2019-16202
Mitre link : CVE-2019-16202
CVE.ORG link : CVE-2019-16202
JSON object : View
Products Affected
misp
- misp
CWE
CWE-269
Improper Privilege Management