Access Control Flaw in MISP Affects User Data Security
CVE-2023-24028
9.8CRITICAL
What is CVE-2023-24028?
In MISP version 2.4.167, a significant access control vulnerability exists within the ACLComponent.php file, specifically affecting the decaying import function. This flaw can allow unauthorized users to gain access to sensitive operations, potentially leading to unauthorized modifications or exposure of critical user data. It is crucial for users of this version to apply necessary patches and review their ACL configurations to ensure robust security measures are in place.
