CVE-2019-9482

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/03/2019
Last modified:
21/07/2021

Description

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:misp:misp:2.4.102:*:*:*:*:*:*:*