Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxpp-9rc5-5w9w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused.

In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused.

EPSS

Процентиль: 57%
0.00354
Низкий

Дефекты

CWE-212

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused.

EPSS

Процентиль: 57%
0.00354
Низкий

Дефекты

CWE-212