CVE-2020-14969: Misp-Project Misp
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
Affected products
- Misp-Project Misp: version 2.4.127 only
Published 2020-06-22. Last modified 2026-06-22.