CVE-2020-14969: Misp-Project Misp

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.

Affected products

Published 2020-06-22. Last modified 2026-06-22.