# MISP patches command injection in STIX import

Published: 2018-12-06 · Severity: medium
Canonical: https://vorant.io/reports/52f0c11b-95e9-53e2-99ef-c22e5909bd94/misp-patches-command-injection-in-stix-import

> MISP 2.4.99 fixes a critical command injection vulnerability (CVE-2018-19908) in its STIX 1 import feature that could be exploited by authenticated users.

MISP, the open-source threat intelligence sharing platform, released version 2.4.99 addressing a critical security vulnerability in its STIX 1 import functionality. The flaw, reported by Francois-Xavier Stellamans of NCI Agency Cyber Security, stemmed from an incorrectly escaped variable containing the original filename of an uploaded STIX file, allowing an authenticated malicious user to inject and execute arbitrary commands on the server hosting MISP.

To remediate the issue, the MISP project replaced the previous mechanism of storing uploaded files and passing them to external tools with a standardized processing function designed to prevent similar injection vulnerabilities from being introduced through future ingestion mechanisms. The release also includes numerous non-security improvements, including new attribute types for x509 certificate fingerprints, UI warning fixes, API corrections for object editing, and enhancements to STIX 1 and STIX 2.0 import handling. Users running MISP instances are strongly urged to upgrade to 2.4.99 to remediate the vulnerability.

## Mentioned in this report

- Vulnerabilities: CVE-2018-19908 (poc)

Source reporting: https://www.misp-project.org/2018/12/06/misp.2.4.99.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/52f0c11b-95e9-53e2-99ef-c22e5909bd94/misp-patches-command-injection-in-stix-import.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
