CVE Vulnerabilities

CVE-2019-16202

Improper Privilege Management

Published: Sep 10, 2019 | Modified: Sep 11, 2019
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115) message.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Misp Misp * 2.4.115 (excluding)

Potential Mitigations

References