MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/MISP/MISP/commit/423750573d07f1a463f115ef37182c1825080da4 | third party advisory patch |
https://github.com/MISP/MISP/compare/v2.4.134...v2.4.135 | third party advisory release notes |