Impact
MISP’s event save workflow incorrectly stores the new distribution and sharing group values instead of the previously persisted ones, causing the correlation engine to fail to detect changes. This flaw allows stale correlations to remain active after an event has been moved to a more restrictive sharing group, potentially exposing threat‑intelligence data to users who should no longer have access. The flaw also means new correlations may never surface when an event’s distribution is widened, decreasing the completeness of threat‑intelligence sharing. The weakness is rooted in improper initialization (CWE‑665) and improper access control (CWE‑284).
Affected Systems
The affected product is MISP, all releases older than 2.5.48. Any user with write access to an event can trigger the flaw if they modify the distribution or sharing_group_id fields.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, suggesting no publicly reported exploit data at this time. Because the flaw requires an authenticated user with write access, exploitation is limited to insiders or compromised credentials. The issue is not currently cataloged in the CISA KEV list, so it has not yet been exploited in the wild. However, once an attacker gains write access to an event, they can force unintended data exposure by altering its distribution or sharing group, making the vulnerability significant for organizations that share sensitive intelligence.
OpenCVE Enrichment