MISP 2.4.182 fixes audit log ACL flaw
MISP 2.4.182 patches a missing ACL control on its new audit logs (CVE-2023-50918), plus various bug fixes and feature updates.
The MISP project released version 2.4.182, addressing a security vulnerability alongside a batch of feature improvements and bug fixes. The key fix, tracked as CVE-2023-50918, resolves a lack of access control list (ACL) enforcement on the newly introduced audit logs feature, which was reported by researcher Fukusuke Takahashi. The audit log feature is not enabled by default, limiting exposure to instances that have explicitly turned it on.
Beyond the security fix, the release includes numerous quality-of-life improvements such as allowing non-privileged users to view server correlations, updates to misp-objects, misp-galaxy, warning-lists, and PyMISP components, and fixes to correlation exclusion handling, event report UUID generation, and password reset logic. This is a routine maintenance release for the MISP threat intelligence platform with one notable low-severity access control fix.
Mentioned in this report
Source reporting: https://www.misp-project.org/2023/12/22/misp.2.4.182.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free