天下漏洞,尽知其名
MEDIUM

CVE-2026-104912 MISP 属性搜索关联授权缺陷漏洞

影响已认证用户可越权读取受限事件的属性与元数据

MEDIUM
暂无 CVSS 评分
AI 研判

MISP 在属性搜索触发关联查询时存在授权缺陷。系统依据关联行上过期的分发快照(缺少 published 标志)而非事件实时访问控制列表进行鉴权,导致事件后续被限制后仍可能被越权访问。

影响范围

MISP

MISP v2.5.48 之前的版本。

漏洞详情

漏洞类型为授权绕过(越权访问)。成因是关联行中的分发字段是创建时的时点副本,未包含发布状态,当事件随后被限制(如更改共享组或取消发布)时,鉴权判断仍基于旧快照。攻击者只需以已认证用户身份执行属性搜索并触发关联查询,即可获取本无权查看的属性和事件详情。

利用条件与风险

利用前提是攻击者拥有实例的已认证账户且对部分事件有读取权限,并存在至少一个在关联创建后被限制的事件。实战中可造成敏感属性值与事件元数据泄露,属信息泄露类风险。

修复建议

升级至 MISP v2.5.48 或更高版本以修复该授权缺陷;暂无公开的临时缓解措施信息。

原始情报

MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.

Because the correlation row’s distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.

Preconditions:

– An authenticated user with at least read access to some events in the instance.

– The existence of correlations between events, at least one of which has been restricted after the correlation was created.

Impact:

– Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.

Affected versions: MISP prior to v2.5.48.