漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
MISP organization administrators can target site administrator accounts for password reset
Vulnerability Description
An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administrative email functionality. The affected code restricted organization administrators to users within their own organization, but did not exclude accounts assigned a site administrator role from recipient queries. As a result, an organization administrator could perform privileged account-management actions, such as initiating a password reset workflow, against a higher-privileged site administrator account in the same organization. Successful exploitation may allow an authenticated organization administrator to interfere with or potentially take over a site administrator account, resulting in privilege escalation and full compromise of the MISP instance’s confidentiality, integrity, and availability. Attack prerequisites: The attacker must be authenticated as an organization administrator in the same organization as a site administrator account.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
MISP 授权问题漏洞
Vulnerability Description
MISP是MISP组织开源的一套开源的软件解决方案。 该产品用于收集、存储、分发、共享网络安全指标,并具有威胁网络安全事件分析和恶意软件分析等功能。 MISP 2.5.40之前版本存在授权问题漏洞,该漏洞源于授权不当,允许同一组织的组织管理员通过管理邮件功能针对站点管理员账户执行特权账户管理操作(如启动密码重置流程),成功利用可能导致权限提升并完全破坏MISP实例的机密性、完整性和可用性。
CVSS Information
N/A
Vulnerability Type
N/A