MISP 在属性搜索过程中的关联处理存在授权缺陷。当用户执行触发关联查找的属性搜索时,系统基于存储在关联行中的过时的分布快照(而非实时的事件访问控制列表)来授权访问关联的属性及事件。 由于关联行中的分布列是某个时间点的静态副本,且不包含“已发布”状态标志,当事件后续被限制访问(例如,其共享组被更改或事件被取消发布)时,授权检查机制将失效。因此,经过身份验证的用户可能能够检索到他们已无权查看的事件所关联的属性及事件详情。 前提条件: 用户已通过身份验证,并且至少对实例中的部分事件拥有只读权限。 事件之间存在关联,且至
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104908 | 7.1 HIGH | MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and D |
| CVE-2026-104906 | 6.2 MEDIUM | MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output |
| CVE-2026-104900 | 5.3 MEDIUM | MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index |
| CVE-2026-104910 | 5.3 MEDIUM | MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization |
| CVE-2026-104914 | 5.3 MEDIUM | MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Pa |
| CVE-2026-104901 | 5.1 MEDIUM | MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Serv |
| CVE-2026-104907 | 4.8 MEDIUM | MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler |
No comments yet