MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
References
Link | Resource |
---|---|
https://github.com/MISP/MISP/commit/f125630c1c2d0f5d11079d3653ab7bb2ab5cd908 | Patch |
https://www.synacktiv.com/publications/php-filter-chains-file-read-from-error-based-oracle | Exploit Third Party Advisory |
https://github.com/MISP/MISP/commit/f125630c1c2d0f5d11079d3653ab7bb2ab5cd908 | Patch |
https://www.synacktiv.com/publications/php-filter-chains-file-read-from-error-based-oracle | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-06-30 17:15
Updated : 2024-11-21 08:11
NVD link : CVE-2023-37306
Mitre link : CVE-2023-37306
CVE.ORG link : CVE-2023-37306
JSON object : View
Products Affected
misp-project
- malware_information_sharing_platform
CWE
CWE-209
Generation of Error Message Containing Sensitive Information