Lucene search

K
cveGitHub_MCVE-2020-11016
HistoryApr 30, 2020 - 11:15 p.m.

CVE-2020-11016

2020-04-3023:15:11
CWE-78
GitHub_M
web.nvd.nist.gov
64
cve-2020-11016
intelmq manager
vulnerability
inspect-tool
webserver
security
nvd

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

AI Score

8.9

Confidence

High

EPSS

0.004

Percentile

72.4%

IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in the “send” functionality of the Inspect-tool of the Monitor component. An attacker with access to the IntelMQ Manager could possibly use this issue to execute arbitrary code with the privileges of the webserver. Version 2.1.1 fixes the vulnerability.

Affected configurations

Nvd
Vulners
Node
intelmq_manager_projectintelmq_managerRange1.1.02.1.1
VendorProductVersionCPE
intelmq_manager_projectintelmq_manager*cpe:2.3:a:intelmq_manager_project:intelmq_manager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "IntelMQ Manager",
    "vendor": "certtools",
    "versions": [
      {
        "status": "affected",
        "version": ">= 1.1.0, < 2.1.1"
      }
    ]
  }
]

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

AI Score

8.9

Confidence

High

EPSS

0.004

Percentile

72.4%

Related for CVE-2020-11016