MISP 2.4.119 patches tag bypass flaw
MISP 2.4.119 fixes a tagging restriction bypass vulnerability (CVE-2019-19379) and adds several usability improvements.
MISP, the open-source threat intelligence sharing platform, released version 2.4.119 addressing CVE-2019-19379, a vulnerability in app/Controller/TagsController.php present in version 2.4.118 that allowed users to bypass intended restrictions on tagging data. The vendor recommends all instances update to the patched version. The issue was reported by Christophe Vandeplas.
Beyond the security fix, the release includes several operational improvements: a new database diagnostics subsystem that compares the live schema against a reference and can generate corrective SQL, expanded timestamp filtering options for attribute searches, a deprecation-tracking system for legacy API endpoints, a refactor of export APIs to use restSearch internally for performance gains, and more reliable sighting synchronisation between servers. Companion misp-modules were also updated with new expansion, export, and import modules.
This is a routine maintenance and patch release for a widely used threat-intel sharing tool rather than an indication of active exploitation; organizations running MISP should apply the update to close the tagging bypass and benefit from the diagnostic and performance improvements.
Mentioned in this report
Source reporting: https://www.misp-project.org/2019/12/04/misp.2.4.119.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free