# MISP 2.4.169 patches two XSS flaws

Published: 2023-03-14 · Severity: low · Sectors: technology
Canonical: https://vorant.io/reports/334fd1cd-7c77-59a0-ac63-69bf4b8ad9e4/misp-2-4-169-patches-two-xss-flaws

> MISP 2.4.169 fixes two XSS vulnerabilities in event-graph tooltips plus adds new features and object support.

The MISP project released version 2.4.169, a routine update to the open-source threat intelligence platform. The release addresses two cross-site scripting vulnerabilities, CVE-2023-28606 and CVE-2023-28607, both located in js/event-graph.js and triggered via malicious content in event-graph node and relationship tooltips. Both issues affect all MISP versions prior to 2.4.169 and are fixed in this release.

Beyond the security fixes, the update includes several feature improvements such as a new Splunk HEC export workflow module, a reworked sighting REST search for performance, dashboard trending-tags filtering enhancements, and a new ApacheSecureAuth authentication scheme. The MISP ecosystem also received updates including new objects (ransomware-group-post, transport-ticket, registry-key-value), a new first-dnsmatrix galaxy for DNS abuse techniques, and new warning lists for captive portals and parking pages. No evidence of active exploitation of the XSS flaws is mentioned; this is a standard maintenance release for MISP administrators to apply.

## Mentioned in this report

- Vulnerabilities: CVE-2023-28606, CVE-2023-28607

Source reporting: https://www.misp-project.org/2023/03/14/misp.2.4.169.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/334fd1cd-7c77-59a0-ac63-69bf4b8ad9e4/misp-2-4-169-patches-two-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
