Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frwx-j879-pmqv

Опубликовано: 08 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write path did not verify event modification rights before saving the module output. This could allow a view-only user to inject or alter event data, impacting the integrity of MISP event content. The issue was fixed by enforcing the same modification-rights check used by related module result handling paths before processing misp_standard imports.

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write path did not verify event modification rights before saving the module output. This could allow a view-only user to inject or alter event data, impacting the integrity of MISP event content. The issue was fixed by enforcing the same modification-rights check used by related module result handling paths before processing misp_standard imports.

EPSS

Процентиль: 13%
0.0022
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862

Связанные уязвимости

nvd
около 2 месяцев назад

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write path did not verify event modification rights before saving the module output. This could allow a view-only user to inject or alter event data, impacting the integrity of MISP event content. The issue was fixed by enforcing the same modification-rights check used by related module result handling paths before processing misp_standard imports.

EPSS

Процентиль: 13%
0.0022
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-862