CyberRota Analysis
AI-GeneratedMISP's API key management is vulnerable, allowing users with a read-only API key to inadvertently gain elevated permissions, including write, delete, or administrative access, if their underlying account has such privileges. This flaw can be exploited with a valid read-only API key and a single request, effectively bypassing intended access controls. Organizations utilizing MISP versions prior to 2.5.47 should prioritize immediate remediation to mitigate the risk of unauthorized access and potential data compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view information. However, after logging in with such a key, a specific MISP function could accidentally restore the user’s normal account permissions. This means someone with a read-only API key could potentially gain write, delete, or even administrator access if their underlying account has those permissions. Exploiting the issue requires a valid read-only API key and a single request to the affected function. The main impact is that MISP’s API key restrictions can be bypassed, allowing actions that the API key was specifically meant to prevent. Version affected: <2.5.47