An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2022-04-22. NVD baseline CVSS 9.8; sources differ by 0.0.
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
April 20, 2022
November 21, 2024
Patch available: MISP/MISP v2.5.11 (contains commit 93821c0de6a7)
https://github.com/MISP/MISP/commit/93821c0de6a7dd32262ce62212773f43136ca66ePatch available: MISP/MISP v2.5.11 (contains commit 0108f1bde211)
https://github.com/MISP/MISP/commit/0108f1bde2117ac5c1e28d124128f60c8bb09a8eMITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-29528
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
CWE-502