MISP 2.4.148 patches two vulnerabilities
MISP released version 2.4.148, fixing CVE-2021-37742 and CVE-2021-37743 along with several bug fixes and feature updates.
MISP, the open-source threat intelligence sharing platform, released version 2.4.148 addressing two security vulnerabilities tracked as CVE-2021-37742 and CVE-2021-37743. The article does not provide technical detail on the nature of these flaws, but their inclusion as dedicated CVEs indicates they were reported as security issues requiring a patch.
Beyond the security fixes, the release includes a new feature to block organisation changes at login when using ApacheShibbAuth, a refactor of the open data export functionality, a fix for Suricata export sticky buffers, and an update to ZMQ pub-sub channels to include the misp_json_warninglist topic. The release also bundles updates to misp-objects, misp-taxonomies, and misp-galaxy. This is a routine maintenance release for administrators of MISP instances to apply to remain current on security patches and feature improvements.
Mentioned in this report
Source reporting: https://www.misp-project.org/2021/08/09/misp.2.4.148.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free