# MISP 2.4.148 patches two vulnerabilities

Published: 2021-08-09 · Severity: low
Canonical: https://vorant.io/reports/0ac99cd6-fb03-50b9-8733-1674f0bf9753/misp-2-4-148-patches-two-vulnerabilities

> MISP 2.4.148 fixes CVE-2021-37742 and CVE-2021-37743 along with several other bugs and feature updates.

The MISP project released version 2.4.148, a maintenance update that addresses two security vulnerabilities tracked as CVE-2021-37742 and CVE-2021-37743, though the article does not detail the specific nature or impact of these flaws. The release also includes non-security improvements such as an option to block organisation changes at login when using ApacheShibbAuth, a refactor of the open data export functionality, a fix for Suricata export handling sticky buffers, and an update to ZMQ pub-sub channels to include the misp_json_warninglist topic.

Additional updates were bundled into the misp-objects, misp-taxonomies, and misp-galaxy components. This is a routine software update advisory with no indication of active exploitation or in-the-wild targeting; organizations running MISP should apply the update to remediate the disclosed vulnerabilities.

## Mentioned in this report

- Vulnerabilities: CVE-2021-37742, CVE-2021-37743

Source reporting: https://www.misp-project.org/2021/08/09/misp.2.4.148.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0ac99cd6-fb03-50b9-8733-1674f0bf9753/misp-2-4-148-patches-two-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
