VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.169 patches XSS flaws

medium vulnerability technology

MISP 2.4.169 fixes two XSS vulnerabilities in event-graph tooltips and adds various platform improvements.

The MISP project released version 2.4.169, a maintenance update addressing two cross-site scripting vulnerabilities (CVE-2023-28606 and CVE-2023-28607) found in js/event-graph.js. Both flaws allow XSS via tooltips on the event-graph node and relationship views in versions prior to 2.4.169, affecting the threat intelligence sharing platform itself rather than data it processes.

Beyond the security fixes, the release bundles a range of feature improvements including a new Splunk HEC export workflow module, a reworked sighting REST search, dashboard trending-tags enhancements, a new ApacheSecureAuth authentication scheme, and fixes to TAXII server baseURL handling and bro export. The MISP object library, galaxy clusters, and warning lists were also expanded, including a new ransomware-group-post object to support ransomlook.io integration and a first-dnsmatrix galaxy for DNS abuse techniques.

This is a routine software update with no indication of active exploitation of the disclosed XSS issues; organizations running MISP should upgrade to 2.4.169 to remediate the vulnerabilities.

Mentioned in this report

Vulnerabilities CVE-2023-28606CVE-2023-28607

Source reporting: https://www.misp-project.org/2023/03/14/misp.2.4.169.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free