# MISP 2.4.156 patches four vulnerabilities

Published: 2022-03-18 · Severity: medium
Canonical: https://vorant.io/reports/083ba357-2710-5d3a-9ed6-9e375da2575f/misp-2-4-156-patches-four-vulnerabilities

> MISP threat-intel platform 2.4.156 fixes SSRF, LFI, XSS, and SVG upload flaws found during a NATO CSC pentest.

The MISP project released version 2.4.156, addressing four security vulnerabilities discovered during a penetration test conducted by Ianis Bernard of the NATO Cyber Security Centre. The issues include an SSRF vulnerability in the generateServerSettings() function (now restricted to CLI only), a local file inclusion (LFI) flaw via custom file settings, unrestricted SVG logo uploads that could carry active payloads, and a stored XSS vulnerability in user add/edit forms exploitable by a malicious administrator via the custom auth name field. The MISP team strongly urges all users to upgrade immediately.

Beyond the security fixes, the release introduces a new 'protected mode' feature enabling cryptographic signing of synchronised events using PGP instance keys, intended to prevent malicious or compromised nodes in a MISP sharing mesh from injecting disinformation or tampering with propagated event data. Additional features include a new HTML context-summary export (including MITRE ATT&CK matrix visualisation), an event warning/quality system, and improvements to LinOTP authentication configuration.

While none of the four CVEs are reported as actively exploited in the wild, they affect a widely deployed open-source threat-intelligence sharing platform used across CERTs, government, and enterprise security teams, making prompt patching advisable given the sensitivity of data typically stored in MISP instances.

## Mentioned in this report

- Vulnerabilities: CVE-2022-27243, CVE-2022-27244, CVE-2022-27245, CVE-2022-27246

Source reporting: https://www.misp-project.org/2022/03/18/misp.2.4.156.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/083ba357-2710-5d3a-9ed6-9e375da2575f/misp-2-4-156-patches-four-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
