CVE-2020-14969
misp
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
- CVSS
- 7.5
- EPSS
- 1.26% 66.6% percentile
- CISA KEV
- Not listed
- Published
- 2020.06.22