MISP 2.4.169 patches two XSS flaws
MISP 2.4.169 fixes two XSS vulnerabilities in event-graph tooltips plus adds new features and object support.
The MISP project released version 2.4.169, a routine update to the open-source threat intelligence platform. The release addresses two cross-site scripting vulnerabilities, CVE-2023-28606 and CVE-2023-28607, both located in js/event-graph.js and triggered via malicious content in event-graph node and relationship tooltips. Both issues affect all MISP versions prior to 2.4.169 and are fixed in this release.
Beyond the security fixes, the update includes several feature improvements such as a new Splunk HEC export workflow module, a reworked sighting REST search for performance, dashboard trending-tags filtering enhancements, and a new ApacheSecureAuth authentication scheme. The MISP ecosystem also received updates including new objects (ransomware-group-post, transport-ticket, registry-key-value), a new first-dnsmatrix galaxy for DNS abuse techniques, and new warning lists for captive portals and parking pages. No evidence of active exploitation of the XSS flaws is mentioned; this is a standard maintenance release for MISP administrators to apply.
Mentioned in this report
Source reporting: https://www.misp-project.org/2023/03/14/misp.2.4.169.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free