In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-02-12T17:00:00Z
Updated: 2024-09-16T20:37:04.758Z
Reserved: 2018-02-12T00:00:00Z
Link: CVE-2018-6926
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-02-12T17:29:00.323
Modified: 2024-11-21T04:11:26.220
Link: CVE-2018-6926
Redhat
No data.