CVE-2024-58130

In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.
Configurations

Configuration 1 (hide)

cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

History

15 Jul 2025, 18:49

Type Values Removed Values Added
First Time Misp
Misp misp
CPE cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
References () https://github.com/MISP/MISP/commit/f08a2eaec25f0212c22b225c0b654bd60d089ef9 - () https://github.com/MISP/MISP/commit/f08a2eaec25f0212c22b225c0b654bd60d089ef9 - Patch
References () https://github.com/MISP/MISP/releases/tag/v2.4.193 - () https://github.com/MISP/MISP/releases/tag/v2.4.193 - Release Notes

01 Apr 2025, 20:26

Type Values Removed Values Added
Summary
  • (es) En app/Controller/Component/RestResponseComponent.php en MISP anterior a 2.4.193, los endpoints REST carecen de depuración para respuestas que no sean JSON.

28 Mar 2025, 23:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

28 Mar 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 22:15

Updated : 2025-07-15 18:49


NVD link : CVE-2024-58130

Mitre link : CVE-2024-58130

CVE.ORG link : CVE-2024-58130


JSON object : View

Products Affected

misp

  • misp
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')