Executive brief
The MISP threat intelligence platform's installer scripts created log files and named pipes with world-readable permissions, allowing any unprivileged local user to read highly sensitive installation data. The exposed credentials included admin passwords, database passwords, GPG passphrases, and supervisor passwords. An attacker with local system access could exploit this to obtain full administrative credentials for the MISP deployment.
Technical details
The installer scripts for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4 used tee and mkfifo to create /var/log/misp_install.log and /var/log/misp_install.log.pipe without explicitly setting restrictive permissions, inheriting the default umask and resulting in 0644 world-readable files. Additionally, the log file was not unlinked before creation, allowing a pre-existing symlink to redirect writes to arbitrary locations. Local unprivileged users could read the log or FIFO during the installation window to extract plaintext credentials.
Affected products
- MISP Project MISP <2.5.47
Timeline
- 2026-09-22: disclosed
- 2026-09: patched: Fix committed to address world-readable permissions and symlink vulnerability