MISP 在基于电子邮件的一次性密码(OTP)登录流程中存在竞态条件漏洞。当两个携带相同有效 OTP 的 HTTP 请求并发提交时,两者均能成功完成身份验证并建立会话。根本原因在于,OTP 值的读取、验证和删除操作是分步执行的,且这些步骤并非原子操作,从而导致第二个进行中的请求可能在第一个请求的删除操作生效之前,读取到相同的 OTP 值。 前提条件: 目标 MISP 实例已启用电子邮件 OTP 登录功能。 攻击者拥有有效的、未过期的 OTP(例如,通过邮件拦截或社会工程学手段获取)。 攻击者能够在时间上非常接近地发
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107180 | 7.1 HIGH | MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instanc |
| CVE-2026-107175 | 5.3 MEDIUM | MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes |
| CVE-2026-107278 | 5.3 MEDIUM | MISP Object Sync Drops Objects and Attributes When Description Is Empty |
No comments yet