MISP 2.4.134 fixes SSRF flaw CVE-2020-28043
MISP 2.4.134 patches a REST client SSRF vulnerability and adds new event reporting, ATT&CK sub-techniques, and optional A/V scanning features.
MISP, the open-source threat intelligence platform, released version 2.4.134 addressing a server-side request forgery vulnerability (CVE-2020-28043) in its REST client. The flaw allowed users to leverage the use_full_path parameter to issue arbitrary queries to any URL, which could be abused to reach internal servers reachable from the MISP instance itself, potentially exposing internal infrastructure to external users. The fix disables the full-path option by default and introduces a new server setting to configure an override base URL, reducing the SSRF attack surface.
Beyond the security fix, the release adds several feature improvements including expanded Event Report functionality with automatic discovery of attributes, galaxies, and tags from captured websites, an optional attachment A/V scanning capability, ATT&CK sub-technique galaxy support, and a sample script for direct STIX 1/2 ingestion. The vulnerability was responsibly reported by Heitor Gouvêa and resolved alongside numerous UI and bug fixes documented in the project's changelog.
This is a routine software maintenance release for a widely used threat-intel sharing platform; the SSRF vulnerability, while notable for CTI infrastructure operators, requires no evidence of active exploitation and is addressed via a straightforward patch and configuration default change.
Mentioned in this report
Source reporting: https://www.misp-project.org/2020/11/10/misp.2.4.134.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free