In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2024-03-21. NVD baseline CVSS 9.8; sources differ by 0.0.
In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
March 21, 2024
June 17, 2025
Patch available: MISP/MISP v2.5.11 (contains commit 6a2986be6aad)
https://github.com/MISP/MISP/commit/6a2986be6aad6b37858b4869e238f517b295c111MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2024-29858
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.