Impact
An improper access control flaw in MISP’s attribute search and paginated view endpoints allows an authenticated user to retrieve soft‑deleted attributes that belong to events owned by other organizations. When a user searches for deleted attributes or views the paginated list with the deleted filter, the application returns all soft‑deleted attributes associated with events their account can read, regardless of the event’s owning organization. This results in the confidential threat intelligence—such as IOCs or contextual information—that the owner intended to remove becoming visible to unauthorized users.
Affected Systems
Vulnerable versions are all releases of MISP prior to v2.5.48. The issue affects the MISP:MISP product in any deployment where users have read access to events owned by other organizations and where the attribute search or paginated view interfaces are exposed to those users.
Risk and Exploitability
The flaw permits confidentiality disclosure; it does not lead to code execution or denial of service. CVSS indicates a medium severity of 5.3. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation may not yet be widespread. The likely attack vector is any authenticated user within the MISP environment who has read access to another organization’s event and who can submit a query for deleted attributes. Exploitation requires no special privileges beyond ordinary event read access.
OpenCVE Enrichment