MISP 2.4.119 patches tag bypass flaw
MISP 2.4.119 fixes a tagging restriction bypass vulnerability (CVE-2019-19379) and adds several usability improvements.
MISP, the open-source threat intelligence sharing platform, released version 2.4.119 addressing CVE-2019-19379, a vulnerability in app/Controller/TagsController.php present in version 2.4.118 that allowed users to bypass intended restrictions on tagging data. The vulnerability was reported by Christophe Vandeplas and has been patched in this release, with the project strongly recommending administrators update.
Beyond the security fix, the release includes several operational improvements: a new database diagnostics sub-system to compare instance schemas against a reference and generate corrective SQL, expanded timestamp filtering options for attribute searches, a new API deprecation tracking system to help administrators migrate away from legacy endpoints, a refactor of export APIs to use restSearch for performance gains, and more reliable sighting synchronization between MISP instances. The misp-modules component was also updated with new expansion, export, and import modules.
This is a routine maintenance and security release for a widely-used threat intelligence sharing platform. The fixed vulnerability is an access-control bypass affecting data tagging rather than a remote code execution or data exposure issue, limiting its practical severity, though organizations running MISP instances should apply the update to maintain proper tag-based access restrictions.
Mentioned in this report
Source reporting: https://www.misp-project.org/2019/12/04/misp.2.4.119.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free