CVE-2022-29534High· 7.5▾ TwilightAn issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.5%
1.5% → 1.6%
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
misp < 2.4.158Upgrade past the affected range:
misp 2.4.158Connected by shared product, vendor, weakness, or advisory.
CVE-2022-29533Medium· 6.1An issue was discovered in MISP before 2.4.158
CVE-2022-29532Medium· 4.8An issue was discovered in MISP before 2.4.158
CVE-2022-29531Medium· 5.4An issue was discovered in MISP before 2.4.158
CVE-2022-29530Medium· 5.4An issue was discovered in MISP before 2.4.158
CVE-2022-29529Medium· 5.4An issue was discovered in MISP before 2.4.158
CVE-2022-29528Critical· 9.8An issue was discovered in MISP before 2.4.158