NVD disclosure day

Published threat advisories for November 17, 2023

CVE advisoryHIGH

CVE-2023-48238

joaquimserafim json-web-token JWT Algorithm Confusion Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in a JavaScript library for JSON Web Tokens could allow an attacker to forge tokens by tricking the library into using an incorrect algorithm for signature verification. This may lead to unauthorized access or actions if the library is used in applications relying on JWTs for authentication or authoriza

CVE advisoryCRITICAL

CVE-2023-48659

MISP Parameter Parsing Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in MISP related to parameter parsing. This flaw could allow an unauthenticated attacker to execute arbitrary code by sending specially crafted requests, potentially compromising sensitive data and the integrity of threat intelligence shared through the system. It is important to confirm

CVE advisoryCRITICAL

CVE-2023-48658

MISP Missing Input Validation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in MISP due to missing input validation, potentially allowing attackers to access and alter data. This flaw, found in a specific model file, could enable malicious activities if reachable. It is important to understand if your MISP instances are affected and the potential consequences for threat

CVE advisoryCRITICAL

CVE-2023-48657

MISP Filter Mishandling Vulnerability CVE-2023-48657

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in MISP's filtering mechanism could allow unauthorized access to or modification of threat intelligence data. This issue stems from mishandled filters in the `AppModel.php` file and may be reachable via network requests. This could impact the integrity and confidentiality of shared data.

CVE advisoryCRITICAL

CVE-2023-48656

MISP Order Clause Mishandling Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in MISP related to how it handles order clauses. This could allow an attacker to manipulate database queries, potentially leading to unauthorized data access or service disruption. Organizations using MISP should assess their exposure to this threat.

CVE advisoryCRITICAL

CVE-2023-48655

MISP Blind SQL Injection via Query Parameter Filtering

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker can exploit a vulnerability in the MISP platform by sending specially crafted requests that manipulate database queries. This could allow unauthorized access to and modification of sensitive data within the application. MISP is commonly used for sharing threat intelligence, making its exposu