Security Advisory

CVE-2021-27904

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-03-02 06:58:00
Last updated 2024-08-03 21:33:16
Assigner mitre
State PUBLISHED

Description

An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.