Описание
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
Ссылки
- Patch
- ExploitThird Party Advisory
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:misp-project:malware_information_sharing_platform:2.4.172:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00299
Низкий
7.5 High
CVSS3
Дефекты
CWE-209
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
EPSS
Процентиль: 53%
0.00299
Низкий
7.5 High
CVSS3
Дефекты
CWE-209