From 41d5d191096286117a6352ad55dd74a2ff903ad1 Mon Sep 17 00:00:00 2001 From: Alexandre Dulaunoy Date: Mon, 28 Jun 2021 11:05:28 +0200 Subject: [PATCH] chg: [security] https://cvepremium.circl.lu/cve/CVE-2021-35502 added --- _pages/security.md | 1 + 1 file changed, 1 insertion(+) diff --git a/_pages/security.md b/_pages/security.md index 3cbb0cb..f0e9fd5 100755 --- a/_pages/security.md +++ b/_pages/security.md @@ -67,6 +67,7 @@ We firmly believe that, even though unfortunately it is often not regarded as co - [CVE-2021-3184](https://cvepremium.circl.lu/cve/CVE-2021-3184) <= MISP 2.4.136 - XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button. - [CVE-2021-27904](https://cvepremium.circl.lu/cve/CVE-2021-27904) <= MISP 2.4.139 - An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors. - [CVE-2021-31780](https://cvepremium.circl.lu/cve/CVE-2021-31780) <= MISP 2.4.141 - an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused. +- [CVE-2021-35502](https://cvepremium.circl.lu/cve/CVE-2021-35502) <= MISP 2.4.144 - app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index. ## PGP Key