Impact
MISP suffered an incorrect authorization flaw that permitted authenticated users to delete attributes from events even when they lacked the required perm_modify or perm_modify_org permissions. The deletion functionality, which relied on organization membership checks in MispAttribute::deleteAttribute(), did not enforce the standard event modification rules. Consequently, a user who belongs to the organization owning an event could remove individual or bulk attributes, disrupting or erasing threat intelligence data without proper authorization.
Affected Systems
The vulnerability affects the open source MISP platform. No specific version ranges are supplied, so any install that has not applied the relevant patch is potentially vulnerable.
Risk and Exploitability
The CVSS score is 8.3, indicating high severity. Abuse requires an authenticated session and membership in the event’s organization, but the exploit does not necessitate elevated privileges beyond that. EPSS data is unavailable, and the flaw is not listed in CISA’s KEV catalog. Attackers could leverage the bypass to alter or delete intelligence, leading to data integrity loss and compromised situational awareness.
OpenCVE Enrichment