VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.107 patches three XSS flaws

medium vulnerability technology

MISP 2.4.107 fixes three persistent XSS vulnerabilities and adds new features like YARA export and object merging.

MISP, the open-source threat intelligence platform, released version 2.4.107 addressing three persistent cross-site scripting vulnerabilities reported by João Lucas Melo Brasio of Elytron Security S.A. The flaws (CVE-2019-11812, CVE-2019-11813, CVE-2019-11814) affect the discussion interface, attribute value fields, and image title handling respectively, allowing JavaScript injection that could execute in the context of other users viewing affected content.

Beyond the security fixes, the release introduces several new capabilities including similar-object detection and merging tools, native YARA and YARA-JSON export functionality, improved API options for warninglist hits and ATT&CK matrix exports, and platform support expansion to OpenBSD 6.5 and Debian 9.9. New MISP modules were also added for document parsing (PDF, PPT, DOCX, XLS) and VMRay sandbox integration.

The vulnerabilities are persistent XSS issues requiring user interaction (e.g., clicking a crafted link) rather than remotely exploitable without interaction. As MISP is widely used by security teams and CERTs for threat intelligence sharing, organizations running self-hosted instances should update to 2.4.107 to mitigate the risk of session hijacking or unauthorized actions via injected scripts within their collaborative platform.

Mentioned in this report

Vulnerabilities CVE-2019-11812CVE-2019-11813CVE-2019-11814

Source reporting: https://www.misp-project.org/2019/05/13/misp.2.4.107.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free