# MISP 2.4.169 patches XSS flaws

Published: 2023-03-14 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/334fd1cd-7c77-59a0-ac63-69bf4b8ad9e4/misp-2-4-169-patches-xss-flaws

> MISP 2.4.169 fixes two XSS vulnerabilities in event-graph tooltips and adds various platform improvements.

The MISP project released version 2.4.169, a maintenance update addressing two cross-site scripting vulnerabilities (CVE-2023-28606 and CVE-2023-28607) found in js/event-graph.js. Both flaws allow XSS via tooltips on the event-graph node and relationship views in versions prior to 2.4.169, affecting the threat intelligence sharing platform itself rather than data it processes.

Beyond the security fixes, the release bundles a range of feature improvements including a new Splunk HEC export workflow module, a reworked sighting REST search, dashboard trending-tags enhancements, a new ApacheSecureAuth authentication scheme, and fixes to TAXII server baseURL handling and bro export. The MISP object library, galaxy clusters, and warning lists were also expanded, including a new ransomware-group-post object to support ransomlook.io integration and a first-dnsmatrix galaxy for DNS abuse techniques.

This is a routine software update with no indication of active exploitation of the disclosed XSS issues; organizations running MISP should upgrade to 2.4.169 to remediate the vulnerabilities.

## Mentioned in this report

- Vulnerabilities: CVE-2023-28606, CVE-2023-28607

Source reporting: https://www.misp-project.org/2023/03/14/misp.2.4.169.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/334fd1cd-7c77-59a0-ac63-69bf4b8ad9e4/misp-2-4-169-patches-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
