CVE-2020-8890Medium· 5.9▾ SunlitAn issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
1.1% → 1.1%
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.
misp < 2.4.121Upgrade past the affected range:
misp 2.4.121Connected by shared product, vendor, weakness, or advisory.
CVE-2020-8892High· 8.1An issue was discovered in MISP before 2.4.121
CVE-2020-8891Medium· 5.9An issue was discovered in MISP before 2.4.121
CVE-2020-8894Medium· 6.5An issue was discovered in MISP before 2.4.121
CVE-2020-8893High· 7.5An issue was discovered in MISP before 2.4.121
CVE-2026-23950High· 8.8node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3
CVE-2026-94277Medium· 6.3MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding