Impact
An unauthenticated SSRF flaw exists in the /fetch_misp_event and /misp_search_events endpoints of cti‑transmute; the server accepts arbitrary hostnames that resolve to internal IP addresses and forwards requests to those addresses, exposing the internal network and allowing the attacker to read responses
Affected Systems
The vulnerability affects installations of the cti‑transmute component provided by MISP that have not yet applied the fix released in commit 4d29109a6f185d5e7c7f3b906f822ab34403f512
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity fault; EPSS is not available and the issue is not listed in KEV. Based on the description, it is inferred that the attack vector involves unauthenticated HTTP requests that trigger DNS resolution to internal IP addresses, enabling the server to reach internal resources if the service is reachable from the outside.
OpenCVE Enrichment