MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2023-02-20. NVD baseline CVSS 9.8; sources differ by 0.0.
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
February 20, 2023
March 18, 2025
Patch available: MISP/MISP v2.5.11 (contains commit afbe08d256d6)
https://github.com/MISP/MISP/commit/afbe08d256d609eee5195c5b0003cfb723ae7af1Patch available: MISP/MISP v2.5.11 (contains commit a73c1c461bc6)
https://github.com/MISP/MISP/commit/a73c1c461bc6f8a048eae92b5e99823afd892d1eMITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-48329
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
CWE-755