---
id: CVE-2021-31780
title: >-
  In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group
  association could lead to information disclosure on an event edit
summary: >-
  In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group
  association could lead to information disclosure on an event edit. When an
  object has a sharing group associated with an event edit, the sharing group
  object is igno…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-212
vendor: misp-project
product: misp
affected:
  - misp = 2.4.141
published: '2021-04-23'
updated: '2026-06-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-31780'
references:
  - url: >-
      https://github.com/MISP/MISP/commit/a0f08501d2850025892e703f40fb1570c7995478
    label: cve@mitre.org
  - url: >-
      https://github.com/MISP/MISP/commit/a0f08501d2850025892e703f40fb1570c7995478
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01047
epssPercentile: 0.62702
ingestedAt: '2026-06-29T13:24:33.473Z'
---

## Overview

In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused.

## Affected

- `misp = 2.4.141`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
