{"id":"CVE-2022-29534","title":"An issue was discovered in MISP before 2.4.158","summary":"An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an \"Accept: application/json\" header.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-287"],"vendor":"misp-project","product":"misp","affected":["misp < 2.4.158"],"patched":["misp 2.4.158"],"published":"2022-04-20","updated":"2026-06-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-29534","references":[{"url":"https://github.com/MISP/MISP/commit/01120163a6b4d905029d416e7305575df31df8af","label":"cve@mitre.org"},{"url":"https://github.com/MISP/MISP/compare/v2.4.157...v2.4.158","label":"cve@mitre.org"},{"url":"https://zigrin.com/advisories/misp-password-confirmation-can-be-bypassed/","label":"cve@mitre.org"},{"url":"https://zigrin.com/cakephp-application-cybersecurity-research-the-impact-of-a-php-vulnerability-exploring-the-password-confirmation-bypass-in-misp/","label":"cve@mitre.org"},{"url":"https://github.com/MISP/MISP/commit/01120163a6b4d905029d416e7305575df31df8af","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/MISP/MISP/compare/v2.4.157...v2.4.158","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://zigrin.com/advisories/misp-password-confirmation-can-be-bypassed/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://zigrin.com/cakephp-application-cybersecurity-research-the-impact-of-a-php-vulnerability-exploring-the-password-confirmation-bypass-in-misp/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01604,"epssPercentile":0.74773,"ingestedAt":"2026-06-29T13:24:33.491Z","slug":"CVE-2022-29534","body":"## Overview\n\nAn issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an \"Accept: application/json\" header.\n\n## Affected\n\n- `misp < 2.4.158`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `misp 2.4.158`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}