CVE-2017-14337
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value, the unauthenticated user can be granted access as an arbitrary user.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.93% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- misp-project/misp
- Source
- cve@mitre.org
References
- https://github.com/MISP/MISP/commit/be111a470204a974c50682054c9c7d4b94396ed9Third Party Advisory
- https://www.circl.lu/advisory/CVE-2017-14337/Third Party Advisory
- https://github.com/MISP/MISP/commit/be111a470204a974c50682054c9c7d4b94396ed9Third Party Advisory
- https://www.circl.lu/advisory/CVE-2017-14337/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.