Skip to content

Commit

Permalink
chg: [security] CVE-2023-50918 added
Browse files Browse the repository at this point in the history
  • Loading branch information
adulau committed Dec 18, 2023
1 parent 7ae7a34 commit 95af1a7
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion content/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,7 @@ We firmly believe that, even though unfortunately it is often not regarded as co
- [CVE-2023-48659](https://cvepremium.circl.lu/cve/CVE-2023-48659) < MISP 2.4.176 - An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
- [CVE-2023-48658](https://cvepremium.circl.lu/cve/CVE-2023-48658) < MISP 2.4.176 - An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
- [CVE-2023-49926](https://cvepremium.circl.lu/cve/CVE-2023-49926) < MISP 2.4.179 - app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

- [CVE-2023-50918](https://cvepremium.circl.lu/cve/CVE-2023-50918) < MISP 2.4.182 - app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for new audit log features (not enabled by default).


## PGP Key
Expand Down

0 comments on commit 95af1a7

Please sign in to comment.