Impact
An authorization flaw exists in MISP’s correlation handling during attribute searches. When a user initiates a search that triggers correlation lookups, the system authorizes access to related events and attributes based on a stale distribution snapshot stored on the correlation row instead of the live event access‑control list. This allows an authenticated user to retrieve the values and metadata of attributes belonging to events they no longer have permission to view, compromising confidentiality.
Affected Systems
All MISP installations running versions prior to 2.5.48 are affected. The vulnerability targets the correlation module used for attribute searches in the open‑source threat‑intelligence platform.
Risk and Exploitability
The flaw can only be exploited by authenticated users possessing at least read access to some events. Once credentials are available, an attacker can trigger correlation lookups through the web UI or API, directly retrieving restricted event and attribute data. With a CVSS score of 7.1 the severity is high; the EPSS is not available, and the vulnerability is not listed in KEV, indicating no widespread exploitation yet but still representing a moderate‑to‑high risk until a patch is applied.
OpenCVE Enrichment