Impact
The vulnerability in MISP occurs during the retrieval of related events for a given event. Instead of verifying each related event against the user's current access rights, the system uses a snapshot stored in the correlation table that lacks published status and can be out of date regarding distribution level or sharing group membership. As a result, an authenticated user can receive metadata—such as titles, dates, and correlation counts—for events they are not allowed to view, allowing reconnaissance of threat‑intelligence information across groups and potentially revealing sensitive event names and timelines.
Affected Systems
MISP products are affected. Any installation of MISP that has not incorporated the fix commit (2ffa97f05) is vulnerable. The fix changes the query logic to apply the full set of authorization checks when constructing the related events list.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity for information disclosure. No EPSS score is available, so the likelihood of immediate exploitation is unclear, but the vulnerability is present in authenticated users who have at least one accessible event and that event is linked to others the user should not see. Because the exploit requires only legitimate credentials and no further privileges, the attack vector can be considered user‑controlled. The vulnerability is not listed in CISA’s KEV catalog at this time, yet the potential for accidental or intentional exposure of event metadata remains a concern for organizations using MISP for threat intelligence sharing.
OpenCVE Enrichment