MISP 2.4.156 patches four vulnerabilities
MISP 2.4.156 fixes SSRF, LFI, and stored XSS flaws found during a NATO Cyber Security Centre pentest, and adds cryptographic signing for trusted synchronisation.
The MISP threat intelligence platform released version 2.4.156, addressing four security vulnerabilities identified during a penetration test conducted by Ianis Bernard of the NATO Cyber Security Centre. The fixes include an SSRF vector in generateServerSettings() (now restricted to CLI use), a local file inclusion issue via custom file settings, a stored XSS vulnerability in the user add/edit forms exploitable via a malicious administrator, and a risk from unrestricted SVG logo uploads that could carry active payloads. The vendor strongly encourages all users to update immediately given the sensitivity of data typically hosted on MISP instances.
Alongside the security patches, the release introduces a new "protected mode" feature that lets event creators attach PGP instance-signing keys to events, cryptographically enforcing which nodes in a MISP sync mesh can propagate legitimate modifications. This is intended to prevent a compromised or malicious node from injecting disinformation or stripping IOCs as data propagates through trust-based sharing networks. Other additions include a context summary export with MITRE ATT&CK matrix visualization, an event quality warning system, and improvements to LinOTP authentication management.
Mentioned in this report
Source reporting: https://www.misp-project.org/2022/03/18/misp.2.4.156.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free