Date: 25.02.2020 Affected Vendor: CIRCL – Computer Incident Response Center Luxembourg Affected Product: MISP – Malware Information Sharing Platform & Open Standards For Threat Information Sharing – https://www.misp-project.org/ Vulnerable Version: 2.4.120 Fixed Version: 2.4.121 CVSS: 6.1 Medium CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Recommendations: Update to MISP version 2.4.121 Vulnerability Details: - Proof of concept alert box: - Proof of concept of API key extraction to localhost web server: CVE: CVE-2020-8893 Credits: Dawid Czarnecki References: - https://www.misp-project.org/2020/02/12/MISP.2.4.121.released.html - https://github.com/MISP/MISP/commit/3d982d92fd26584115c01f8c560a688d1096b65c - https://nvd.nist.gov/vuln/detail/CVE-2020-8893