Impact
MISP implements a discussion posting feature that was designed to restrict access to threads based on organization membership. In this vulnerability, the application only verified whether a thread was flagged as restricted to a single organization. It failed to enforce the broader thread access control list that includes sharing-group membership and event-level visibility. As a result, an authenticated user who does not belong to the sharing group or lack visibility on the corresponding event can read the thread title, view the content of quoted posts, and append new messages to the discussion thread. The data disclosure extends to restricted thread metadata and post content, while the integrity impact allows injection of unauthorized messages.
Affected Systems
The vulnerability affects MISP deployments running versions earlier than 2.5.48.
Risk and Exploitability
The vulnerability scores a CVSS of 5.3, indicating moderate severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation in the wild. An attacker must be authenticated to a MISP instance and have access to the application’s posting interface. Because the flaw is limited to threads that are incorrectly checked for organization-only distribution, the most likely attack vector is an internal authenticated user exploiting the posting function. The exploitation requires no special configuration beyond normal user credentials, and the attacker can gain information disclosure and tamper with discussions within the organization.
OpenCVE Enrichment