Impact
The vulnerability causes the AccessLog model to record duplicate log entries for the same HTTP request. When an exception occurs, CakePHP runs the application startup path a second time, leading to a second call to AccessLog::logRequest() during the same request. The second call overwrites the original log row, corrupting fields such as request duration, SQL query count, memory usage, and potentially the query log, thereby destroying forensic data and compromising audit integrity. The flaw is a result of improper response handling (CWE‑223) and unsafe shared resource usage (CWE‑778).
Affected Systems
MISP instances running version 2.5.45 or earlier are affected. The issue applies to any M, because the AccessLog model reuses a single instance and retains the row ID.
Risk and Exploitability
Based on the description, it is inferred that an attacker could trigger the double‑write by causing an exception – for example, by sending malformed data that leads to a fatal error a CVSS v3.1 score of 5.3, the vulnerability is classified as moderate severity. The EPSS score is less than 1 %, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. The impact is limited to the integrity of audit logs; no elevation of privilege or direct data theft occurs.
OpenCVE Enrichment