Vulnerabilities > CVE-2020-14969 - Missing Authorization vulnerability in Misp 2.4.127

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
misp
CWE-862

Summary

app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.

Vulnerable Configurations

Part Description Count
Application
Misp
1

Common Weakness Enumeration (CWE)