CVE-2023-37306: Misp-Project Misp
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
Affected products
- Misp-Project Misp: version 2.4.172 only
Published 2023-06-30. Last modified 2026-06-23.