MISP 2.4.175 patches two XSS flaws
MISP 2.4.175 fixes two reflected XSS vulnerabilities affecting versions up to 2.4.174, alongside various bug fixes and feature improvements.
The MISP project released version 2.4.175, addressing two reflected cross-site scripting (XSS) vulnerabilities affecting all versions up to and including 2.4.174. CVE-2023-40224 affects the events index view, while CVE-2023-41098 impacts the Dashboards controller via the id parameter used when editing a dashboard. Both were reported by the BeDisruptive OSS Team, with CVE-2023-41098 also credited to the Centre for Cyber Security Belgium (CCB).
Beyond the security fixes, this release includes a number of quality-of-life improvements such as enhanced dashboard widget timeframe options, a new generic enrichment functionality for MISP objects, new feeds, and updated object templates for better STIX 2.1 support. Several bug fixes were also made to the JSON import process, API endpoints, and dashboard interface. Updates to the threat actor and tool galaxies, Sigma galaxy, and warning-lists (including new Zscaler and OpenAI crawler IP sources) round out the release.
This is a routine software maintenance advisory rather than an active exploitation event. The XSS issues are low-complexity web vulnerabilities in a threat-intelligence platform and warrant prompt patching by MISP operators, but there is no indication of in-the-wild exploitation or targeting.
Mentioned in this report
Source reporting: https://www.misp-project.org/2023/08/24/misp.2.4.175.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free