Review reviewHigh
CVE-2020-28043
misp
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
- CVSS
- 7.5
- EPSS
- 1.31% 67.9% percentile
- CISA KEV
- Not listed
- Published
- 2020.11.03
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
The CVSS severity warrants an early asset and exposure review.
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
Confirm exposure before applying a vendor-supported change.
Confirm that misp and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.