Vulnerabilidades em MISP

58 resultados
Análise Vexday

O MISP apresenta 13 vulnerabilidades catalogadas, sendo 5 divulgadas nos últimos 90 dias, o que indica atividade contínua de descoberta de falhas. Embora nenhuma esteja sob ataque ativo no momento, 2 vulnerabilidades críticas e a predominância de injeção de conteúdo (CWE-79) requerem atenção, especialmente considerando o papel estratégico da plataforma em ecossistemas de compartilhamento de inteligência de ameaças.

CVE-2024-58128MEDIUMIn MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin EPSS 0.2%CVE-2026-54362MEDIUMMISP template builder exposes non-visible custom galaxies across organisationsEPSS 0.2%CVE-2026-60125MEDIUMimportModule function in MISP ignores per-organisation import module restrictionsEPSS 0.2%CVE-2026-10860HIGHMISP CRUDComponent delete validation bypass via operator precedence errorEPSS 0.2%CVE-2026-54359HIGHMISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by defaultEPSS 0.2%CVE-2026-44364CRITICALmisp-modules website - Missing CSRF protection in the website home blueprintEPSS 0.2%CVE-2026-9084MEDIUMMISP OIDC authentication bypass via automatic email-based account linking under insecure IdP configurationsEPSS 0.2%CVE-2026-44379MEDIUMMISP: Improper UUID validation in MISP CollectionsEPSS 0.2%CVE-2026-10864MEDIUMMISP Dashboard widget field selection may expose restricted user and organisation dataEPSS 0.2%CVE-2026-10854MEDIUMUnauthorized exposure of private galaxies in MISP event template creationEPSS 0.2%CVE-2026-10855MEDIUMMISP Event template importer authorization bypassEPSS 0.2%CVE-2026-10856MEDIUMOpen redirect in MISP dashboard button widget URL handlingEPSS 0.1%CVE-2026-8080MEDIUMMISP core - Stored XSS in MISP template (old engine) element attribute typeEPSS 0.1%CVE-2026-44363MEDIUMUnsafe remote resource fetching in expansion misp-modulesEPSS 0.1%CVE-2026-72751MEDIUMStored Cross-Site Scripting in CTI-Transmute Conversion Graph via Malicious STIX/MISP ContentEPSS CVE-2026-71502MEDIUMUnauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-TransmuteEPSS CVE-2026-72760MEDIUMcti-transmute Following List Exposes User Email Addresses to Authenticated UsersEPSS CVE-2026-72759MEDIUMcti-transmute Conversion History Authorization Bypass Leads to Sensitive Data Disclosure After Conversion DeletionEPSS