# MISP 2.4.128 fixes CVE-2020-14969 ACL flaw

Published: 2020-06-24 · Severity: low · Sectors: technology
Canonical: https://vorant.io/reports/6439880a-0e69-59d4-8576-36a1fc15fbcc/misp-2-4-128-fixes-cve-2020-14969-acl-flaw

> MISP 2.4.128 patches an attribute correlation ACL bypass and adds major STIX import/export refactoring.

MISP released version 2.4.128, addressing CVE-2020-14969, a vulnerability in which app/Model/Attribute.php lacked an ACL lookup on attribute correlations. This flaw allowed the attribute restsearch API to expose metadata about a correlating but otherwise unreachable attribute, potentially leaking information to users who should not have visibility into it.

Beyond the security fix, this release includes a significant refactoring of STIX 1 and 2 import/export functionality, contributed by Christian Studer. The most notable improvement automatically maps imported threat-actor, tool, and similar data-points to existing MISP galaxy entries, linking synonyms found in STIX files to known galaxy clusters and tags. Additional changes include CIDR correlation support for ip-src|port and ip-dst|port types and a new authentication failure dashboard widget sourced from the D4 project, along with broader updates to misp-objects, misp-taxonomies, and misp-galaxy.

This is a routine software update and vulnerability disclosure for a widely used threat-intelligence sharing platform rather than an active exploitation event. Organizations running MISP should upgrade to 2.4.128 to remediate the ACL bypass and benefit from the STIX processing improvements.

## Mentioned in this report

- Vulnerabilities: CVE-2020-14969

Source reporting: https://www.misp-project.org/2020/06/24/misp.2.4.128.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6439880a-0e69-59d4-8576-36a1fc15fbcc/misp-2-4-128-fixes-cve-2020-14969-acl-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
