MISP 2.4.148 patches two vulnerabilities
MISP 2.4.148 fixes CVE-2021-37742 and CVE-2021-37743 along with several other bugs and feature updates.
The MISP project released version 2.4.148, a maintenance update that addresses two security vulnerabilities tracked as CVE-2021-37742 and CVE-2021-37743, though the article does not detail the specific nature or impact of these flaws. The release also includes non-security improvements such as an option to block organisation changes at login when using ApacheShibbAuth, a refactor of the open data export functionality, a fix for Suricata export handling sticky buffers, and an update to ZMQ pub-sub channels to include the misp_json_warninglist topic.
Additional updates were bundled into the misp-objects, misp-taxonomies, and misp-galaxy components. This is a routine software update advisory with no indication of active exploitation or in-the-wild targeting; organizations running MISP should apply the update to remediate the disclosed vulnerabilities.
Mentioned in this report
Source reporting: https://www.misp-project.org/2021/08/09/misp.2.4.148.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free