poslední zpráva
SPOJENO AI EPSS 0.00 (nejvyšší)
MISP security advisory (AV26-986)
Serial number: AV26-986 Date: October 1, 2026 As of October 1, 2026, MISP is affected by vulnerabilities in the following product: MISP Prior to 2.5.48 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Delegation requests stay bound to the event they were authorised for A nested model alias key no longer selects the row a save targets Tag collection saves no longer write sibling user/org rows Refuse a…
MISP CA IT FI
CVE v události 6
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-103235 | 8.7 4.0 · CIRCL | – | 0.00 |
| CVE-2026-103237 | 8.3 4.0 · CIRCL | – | 0.00 |
| CVE-2026-103239 | 8.6 4.0 · CIRCL | – | 0.00 |
| CVE-2026-103321 | 8.3 4.0 · CIRCL | – | 0.00 |
| CVE-2026-103388 | 6.2 4.0 · CIRCL | – | 0.00 |
| CVE-2026-103389 | 6.2 4.0 · CIRCL | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 6.2.
Jak se o tom psalo 3
-
· Cyber Centre Kanada CA nadpis události
MISP security advisory (AV26-986)
Serial number: AV26-986 Date: October 1, 2026 As of October 1, 2026, MISP is affected by vulnerabilities in the following product: MISP Prior to 2.5.48 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Delegation requests stay bound to the event they were authorised for A nested model alias key no longer selects the row a save targets Tag collection saves no longer write sibling user/org rows Refuse a…
-
· CSIRT Itálie (ACN) IT
Risolte vulnerabilità in MISP
Aggiornamenti di sicurezza risolvono molteplici vulnerabilità, di cui 4 con gravità "alta", in MISP, nota piattaforma collaborativa open source per la condivisione e l'analisi di informazioni sulle minacce informatiche.
-
· zachyceno · NCSC-FI FI
Vulnerabilities in MISP
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 6.2, CVEs: CVE-2026-103388, CVE-2026-103389, CVE-2026-103321, Summary: CVE-2026-103388 (CVSS: 6.2): MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a…