CVE-2023-37306: Misp-Project Misp

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

Affected products

Published 2023-06-30. Last modified 2026-06-23.