MISP 2.4.169 patches XSS flaws
MISP 2.4.169 fixes two XSS vulnerabilities in event-graph tooltips and adds various platform improvements.
The MISP project released version 2.4.169, a maintenance update addressing two cross-site scripting vulnerabilities (CVE-2023-28606 and CVE-2023-28607) found in js/event-graph.js. Both flaws allow XSS via tooltips on the event-graph node and relationship views in versions prior to 2.4.169, affecting the threat intelligence sharing platform itself rather than data it processes.
Beyond the security fixes, the release bundles a range of feature improvements including a new Splunk HEC export workflow module, a reworked sighting REST search, dashboard trending-tags enhancements, a new ApacheSecureAuth authentication scheme, and fixes to TAXII server baseURL handling and bro export. The MISP object library, galaxy clusters, and warning lists were also expanded, including a new ransomware-group-post object to support ransomlook.io integration and a first-dnsmatrix galaxy for DNS abuse techniques.
This is a routine software update with no indication of active exploitation of the disclosed XSS issues; organizations running MISP should upgrade to 2.4.169 to remediate the vulnerabilities.
Mentioned in this report
Source reporting: https://www.misp-project.org/2023/03/14/misp.2.4.169.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free