# MISP 2.4.93 patches brute-force bypass flaw

Published: 2018-06-27 · Severity: low · Sectors: technology
Canonical: https://vorant.io/reports/247fbe7f-822a-59f4-a93c-4bc240db2c0f/misp-2-4-93-patches-brute-force-bypass-flaw

> MISP 2.4.93 adds a MITRE ATT&CK interface and event locking while fixing CVE-2018-12649, a brute-force protection bypass.

The MISP project released version 2.4.93, a routine maintenance and feature release for the open-source threat intelligence platform. Key additions include a tightly integrated MITRE ATT&CK matrix interface for tagging events and attributes with adversarial tactics and techniques, a new event-locking feature to prevent concurrent edit conflicts, initial multilingual UI support, and improvements to STIX 1/2 import and export capabilities.

The release also addresses a security vulnerability, CVE-2018-12649, which allowed attackers to bypass MISP's brute-force login protection via PUT requests. This is a defensive-tooling patch advisory with no indication of active exploitation in the wild; the fix is bundled alongside numerous bug fixes and usability improvements. Organizations running MISP should update to 2.4.93 and refresh galaxies, objects, and taxonomies via git submodule update.

## Mentioned in this report

- Vulnerabilities: CVE-2018-12649

Source reporting: https://www.misp-project.org/2018/06/27/misp.2.4.93.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/247fbe7f-822a-59f4-a93c-4bc240db2c0f/misp-2-4-93-patches-brute-force-bypass-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
