MISP 受影响的交互式 CLI Shell 版本在审计日志中无法可靠地保留被模拟的 MISP 用户身份。 该 Shell 设计为以指定的 MISP 用户 ID 执行操作。然而,旧版 SysLogLogable 行为将用户身份存储在行为实例状态中,当其他模型懒加载挂载共享行为时,该身份可能会被覆盖。因此,后续的 CLI 写入操作可能会丢失预期的用户归属信息,并导致日志记录错误。此外,提交说明还指出,源自 CLI 的记录缺少 CLI 标记,使得这些记录在日志中看起来与普通 Web 操作无异。 受影响版本:≤ 2.5.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90961 | 9.3 CRITICAL | MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials |
| CVE-2026-90895 | 8.4 HIGH | MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Inject |
| CVE-2026-90893 | 5.1 MEDIUM | MISP UserSettingsController CSRF Protection Bypass on setTheme, setHomePage, and eventInde |
| CVE-2026-90957 | 5.1 MEDIUM | MISP: Stored XSS via Inline-Served SVG Organisation Logos and Report Pictures |
No comments yet