MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115) message.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Misp | Misp | * | 2.4.115 (excluding) |