Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes
Vulnerability Description
MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified.
When a user edits an existing event and changes its distribution or sharing_group_id, the internal before-save hook stored the incoming (new) data rather than the previously persisted values. As a result, the after-save comparison that determines whether a correlation refresh is needed never detected the change, and stale correlations persisted.
Security impact:
- Stale correlations may continue to expose event data to users in a broader sharing group after the event has been moved to a more restrictive group, resulting in unintended information disclosure.
- Conversely, newly relevant correlations may not appear after a distribution widening, degrading the completeness of threat intelligence sharing.
Preconditions:
- An authenticated user with write access to at least one MISP event.
- The user modifies the event's distribution or sharing_group_id field.
Affected versions: <2.5.48
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Vulnerability Type
访问控制不恰当