MISP patches command injection in STIX import
MISP 2.4.99 fixes a critical command injection vulnerability (CVE-2018-19908) in its STIX 1 import feature that could be exploited by authenticated users.
MISP, the open-source threat intelligence sharing platform, released version 2.4.99 addressing a critical security vulnerability in its STIX 1 import functionality. The flaw, reported by Francois-Xavier Stellamans of NCI Agency Cyber Security, stemmed from an incorrectly escaped variable containing the original filename of an uploaded STIX file, allowing an authenticated malicious user to inject and execute arbitrary commands on the server hosting MISP.
To remediate the issue, the MISP project replaced the previous mechanism of storing uploaded files and passing them to external tools with a standardized processing function designed to prevent similar injection vulnerabilities from being introduced through future ingestion mechanisms. The release also includes numerous non-security improvements, including new attribute types for x509 certificate fingerprints, UI warning fixes, API corrections for object editing, and enhancements to STIX 1 and STIX 2.0 import handling. Users running MISP instances are strongly urged to upgrade to 2.4.99 to remediate the vulnerability.
Mentioned in this report
Source reporting: https://www.misp-project.org/2018/12/06/misp.2.4.99.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free