天下漏洞,尽知其名
HIGH

CVE-2026-103237 MISP ORM 输入验证不当漏洞

影响认证用户可越权篡改、迁移或软删除其他组织的数据

AI 研判

MISP 的 ORM 保存路径存在输入验证不当问题。应用在净化扁平记录时会剥离主键并将 event_id/object_id 固定为调用者上下文,但底层 ORM 的 set() 方法会优先采用与模型别名同名的嵌套键,从而丢弃外层标量字段。攻击者可在请求中嵌入模型别名下的嵌套块,使 ORM 绑定到携带攻击者指定 id 和 event_id 的内层记录,绕过净化逻辑。

影响范围

MISP

受影响版本范围暂无公开信息,涉及 MISP 的 ORM 保存路径相关功能。

漏洞详情

漏洞类型为输入验证不当导致的越权数据操作。成因是外层记录净化与 ORM 实际绑定的内层记录不一致:净化作用于外层,而 ORM 优先绑定攻击者可控的内层嵌套记录。利用方式为拥有基本写权限的认证用户在 attribute add/edit、event edit、自由文本导入、sighting 捕获、shadow attribute 提议、event report 创建、object reference 添加、用户管理编辑等端点提交含嵌套模型别名键的请求,从而覆盖、重新归属或软删除其他组织或事件的行。

利用条件与风险

利用前提是攻击者拥有基本写权限的认证账户,实战中可造成跨租户数据完整性破坏,风险较高。

修复建议

官方修复方案暂无公开信息,建议关注 MISP 官方安全公告并及时升级;临时缓解措施包括限制写权限账户、审计相关端点的异常嵌套请求。

原始情报

MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the flat record by stripping the primary key and pinning the event_id or object_id to the caller’s context. However, the underlying ORM’s set() method gives priority to a nested key whose name matches the model alias and discards the outer scalar fields.

An authenticated user with basic write permissions can exploit this by embedding a nested block under the model alias key inside their request. The sanitization logic (id removal, event_id pinning) is applied to the outer record, but the ORM binds to the inner record instead, which carries an attacker-chosen id and event_id. This allows the attacker to overwrite, re-parent, or soft-delete rows belonging to other organizations or events they have no read access to.

Impact:

– Cross-tenant data integrity compromise (attribute values rewritten, objects re-parented to attacker events, rows soft-deleted)

– Affects multiple entity types: Attribute, Object, EventReport, Sighting, AttributeTag, ShadowAttribute

– Requires only a low-privilege authenticated account with perm_add

Affected versions: <2.5.48