Impact
Affected MISP dashboards had inconsistent authorization checks that let authenticated users without the perm_sharing_group permission enumerate organisation information that was intended to remain hidden. The widgets returned organisation names, identifiers, and full database rows via JSON export, and accepting limit values of 0 or negative numbers allowed the entire organisation table to be retrieved. A leaderboard component also ignored visibility settings, revealing organisations that had events even when the caller could not view those events. This constitutes a confidentiality breach, exposing sensitive organisational details to unauthorized users.
Affected Systems
The vulnerability exists in the MISP platform from the MISP codebase, affecting all releases up to and including version 2.5.45. It specifically targets dashboard widgets and the organisation leaderboard that display organisational information.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity risk. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an authenticated user session with access to the MISP web interface, and the vulnerability does not provide for remote code execution or privilege escalation. Once accessed, the flaw enables enumeration and disclosure of organisational data, which is a compliance and privacy concern for organizations using MISP.
OpenCVE Enrichment