Impact
Affected MISP versions allow outbound HTTP requests to untrusted destinations during feed retrieval and TAXII discovery. Redirects are followed without validating the scheme or target, and authentication headers can be stolen and reused against another host. The lack of internal destination checks also permits a remote attacker to trigger server‑side request forgery, reaching internal services and exposing credentials.
Affected Systems
MISP – Versions 2.5.45 and earlier.
Risk and Exploitability
The CVSS score of 7.0 indicates a medium‑to‑high severity vulnerability. EPSS is not available, and the issue is not listed in CISA’s KEV catalog. The described weaknesses allow a remote attacker, for example by configuring a malicious feed URL or manipulating the TAXII discovery endpoint, to perform SSRF against internal resources or to cause credentials to be forwarded to an external party. If the attacker controls the redirect target, they can direct requests to any host reachable from the MISP server.
OpenCVE Enrichment