Impact
The vulnerability in cti-transmute allows a user with permission to view a conversion to export its evaluation report in Markdown or PDF format and retrieve evaluation comments that should only be visible to the conversion owner, comment author, or administrators. The export also reveals the comment author's name, thereby leaking private evaluation content. This is an information disclosure flaw rooted in missing enforcement of comment‑level access control during report generation.
Affected Systems
The affected products are versions of MISP’s cti‑transmute module, as identified by the CNA vendor MISP:cti‑transmute. The exact product version range is not supplied in the data, but any release lacking the access control patch is susceptible. Users running these unpatched versions should consider them at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity with a typical attack scenario involving a legitimate user exploiting an authorized action. The EPSS score is not available, so exploit likelihood is unknown, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a legitimate‑user‑based privilege abuse: a user who can view a conversion can trigger the export and obtain the data. No additional prerequisites or remote code execution paths are indicated.
OpenCVE Enrichment