app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.
References
Configurations
History
20 Sep 2024, 18:14
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 | |
CPE | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
First Time |
Misp
Misp misp |
|
References | () https://github.com/MISP/MISP/commit/3a5227d7b3d4518ac109af61979a00145a0de6fa - Patch | |
References | () https://github.com/MISP/MISP/compare/v2.4.197...v2.4.198 - Patch | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
17 Sep 2024, 16:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
16 Sep 2024, 15:30
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Sep 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-15 20:15
Updated : 2024-09-20 18:14
NVD link : CVE-2024-46918
Mitre link : CVE-2024-46918
CVE.ORG link : CVE-2024-46918
JSON object : View
Products Affected
misp
- misp
CWE
CWE-863
Incorrect Authorization