# MISP 2.4.134 fixes SSRF flaw CVE-2020-28043

Published: 2020-11-10 · Severity: medium
Canonical: https://vorant.io/reports/3b61eec5-1320-5a04-8e1f-f688f0cc00fa/misp-2-4-134-fixes-ssrf-flaw-cve-2020-28043

> MISP 2.4.134 patches an SSRF vulnerability in its REST client and adds new Event Report and A/V scanning features.

MISP released version 2.4.134, which introduces several new features including automatic discovery of attributes, galaxies, and tags from captured websites within the Event Report functionality, optional attachment A/V scanning, ATT&CK sub-technique support as a galaxy, and an example script for direct STIX ingestion.

The release also addresses CVE-2020-28043, a server-side request forgery (SSRF) vulnerability affecting MISP through version 2.4.133. The flaw exists in the REST client's use_full_path parameter, which allowed users to issue queries to arbitrary URLs. This is particularly problematic in deployments where the MISP server has network access to internal servers, as external users could leverage the SSRF to trigger unauthorized queries against those internal systems. The fix disables the full path option by default and introduces new server settings, including an override baseurl option, to mitigate the risk while preserving legitimate use cases such as training VMs with port forwarding.

The vulnerability was reported by Heitor Gouvêa. This is a routine software update with a moderate-severity security fix rather than an actively exploited threat.

## Mentioned in this report

- Vulnerabilities: CVE-2020-28043

Source reporting: https://www.misp-project.org/2020/11/10/misp.2.4.134.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3b61eec5-1320-5a04-8e1f-f688f0cc00fa/misp-2-4-134-fixes-ssrf-flaw-cve-2020-28043.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
