MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115)" message.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://github.com/MISP/MISP/commit/75acd63c46506ad404764c3a3de7d4ca11d0560f | third party advisory patch |
https://github.com/MISP/MISP/compare/v2.4.114...v2.4.115 | third party advisory patch |
https://excellium-services.com/cert-xlm-advisory/cve-2019-16202/ | third party advisory |