CVE-2017-14337 describes a critical authentication bypass vulnerability in MISP versions prior to 2.4.80. When MISP is configured for X.509 certificate authentication alongside an external user management API, an unauthenticated attacker can gain access as an arbitrary user if the external API returns an empty value. This vulnerability carries a CVSSv3 score of 8.1 (High), indicating a network-exploitable flaw with high impact on confidentiality, integrity, and availability, despite requiring high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.79CPE matchmatch criteria | cpe:2.3:a:misp-project:misp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.