The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-11-25T18:00:00

Updated: 2017-11-25T18:57:01

Reserved: 2017-11-25T00:00:00


Link: CVE-2017-16946

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-11-25T18:29:00.220

Modified: 2017-12-07T20:08:59.977


Link: CVE-2017-16946

JSON object: View

cve-icon Redhat Information

No data.

CWE