VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.156 patches four vulnerabilities

routine vulnerability

MISP 2.4.156 fixes SSRF, LFI, and stored XSS flaws found during a NATO Cyber Security Centre pentest, and adds cryptographic signing for trusted synchronisation.

The MISP threat intelligence platform released version 2.4.156, addressing four security vulnerabilities identified during a penetration test conducted by Ianis Bernard of the NATO Cyber Security Centre. The fixes include an SSRF vector in generateServerSettings() (now restricted to CLI use), a local file inclusion issue via custom file settings, a stored XSS vulnerability in the user add/edit forms exploitable via a malicious administrator, and a risk from unrestricted SVG logo uploads that could carry active payloads. The vendor strongly encourages all users to update immediately given the sensitivity of data typically hosted on MISP instances.

Alongside the security patches, the release introduces a new "protected mode" feature that lets event creators attach PGP instance-signing keys to events, cryptographically enforcing which nodes in a MISP sync mesh can propagate legitimate modifications. This is intended to prevent a compromised or malicious node from injecting disinformation or stripping IOCs as data propagates through trust-based sharing networks. Other additions include a context summary export with MITRE ATT&CK matrix visualization, an event quality warning system, and improvements to LinOTP authentication management.

Mentioned in this report

Vulnerabilities CVE-2022-27243CVE-2022-27244CVE-2022-27245CVE-2022-27246

Source reporting: https://www.misp-project.org/2022/03/18/misp.2.4.156.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free