CVE Vulnerabilities

CVE-2021-27904

Published: Mar 02, 2021 | Modified: Mar 08, 2021
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the all org flag sometimes provided view access to unintended actors.

Affected Software

Name Vendor Start Version End Version
Misp Misp * 2.4.139

References