MISP 2.4.182 fixes audit log ACL flaw
MISP 2.4.182 patches a missing access-control vulnerability in its new audit logs feature, alongside various bug fixes and improvements.
The MISP project released version 2.4.182 of its open-source threat-intelligence platform, addressing a security issue tracked as CVE-2023-50918. The flaw stemmed from the newly introduced audit logs feature lacking proper ACL (access control list) handling, meaning access restrictions were not correctly enforced. The issue was reported by researcher Fukusuke Takahashi and has been fixed by adding proper ACL checks; the affected audit log feature is not enabled by default, limiting real-world exposure.
Beyond the security fix, the release includes numerous functional improvements and bug fixes across MISP core, including updates to misp-objects, misp-stix, warning-lists, misp-galaxy, and PyMISP components, as well as fixes to correlation exclusion logic, event report handling, and login history. This is a routine maintenance release with no evidence of active exploitation; the security fix is precautionary given the non-default status of the vulnerable feature.
Mentioned in this report
Source reporting: https://www.misp-project.org/2023/12/22/misp.2.4.182.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free