CVE-2018-6926

Source
https://cve.org/CVERecord?id=CVE-2018-6926
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6926.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-6926
Published
2018-02-12T17:29:00.323Z
Modified
2026-08-07T14:59:32.695087Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rhshellfix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

References

Affected packages

Git / github.com/misp/misp

Affected ranges

Type
GIT
Repo
https://github.com/misp/misp
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:misp-project:misp:2.4.87:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.4.87"
        },
        {
            "last_affected": "2.4.87"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.4.87
v2.*
v2.4.87

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6926.json"