CVE-2017-14337
Summary
| CVE | CVE-2017-14337 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-12 16:29:00 UTC |
| Updated | 2017-09-29 15:11:00 UTC |
| Description | When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value, the unauthenticated user can be granted access as an arbitrary user. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Misp-project | Misp | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix: Fix to certauth pains · MISP/MISP@be111a4 · GitHub | CONFIRM | github.com | Third Party Advisory |
| CIRCL » CVE-2017-14337 - Vulnerability in MISP (Malware Information Sharing Platform) and Threat Sharing - Vulnerability in CertAuth module when used with external user management API | CONFIRM | www.circl.lu | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.