MISP 2.4.156 patches four vulnerabilities
MISP threat-intel platform 2.4.156 fixes SSRF, LFI, XSS, and SVG upload flaws found during a NATO CSC pentest.
The MISP project released version 2.4.156, addressing four security vulnerabilities discovered during a penetration test conducted by Ianis Bernard of the NATO Cyber Security Centre. The issues include an SSRF vulnerability in the generateServerSettings() function (now restricted to CLI only), a local file inclusion (LFI) flaw via custom file settings, unrestricted SVG logo uploads that could carry active payloads, and a stored XSS vulnerability in user add/edit forms exploitable by a malicious administrator via the custom auth name field. The MISP team strongly urges all users to upgrade immediately.
Beyond the security fixes, the release introduces a new 'protected mode' feature enabling cryptographic signing of synchronised events using PGP instance keys, intended to prevent malicious or compromised nodes in a MISP sharing mesh from injecting disinformation or tampering with propagated event data. Additional features include a new HTML context-summary export (including MITRE ATT&CK matrix visualisation), an event warning/quality system, and improvements to LinOTP authentication configuration.
While none of the four CVEs are reported as actively exploited in the wild, they affect a widely deployed open-source threat-intelligence sharing platform used across CERTs, government, and enterprise security teams, making prompt patching advisable given the sensitivity of data typically stored in MISP instances.
Mentioned in this report
Source reporting: https://www.misp-project.org/2022/03/18/misp.2.4.156.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free