# MISP 2.4.164 patches org-admin role leak

Published: 2022-10-10 · Severity: low
Canonical: https://vorant.io/reports/71009f72-3665-59cc-ab1a-b4a11d654636/misp-2-4-164-patches-org-admin-role-leak

> MISP released version 2.4.164, adding tag relationship features and fixing CVE-2022-42724, which let org admins see restricted role names.

MISP, the open-source threat intelligence sharing platform, has released version 2.4.164. The update introduces a new tag relationship feature allowing analysts to link relationships between attribute or event tags and galaxy clusters, both via the UI and a new API endpoint. Additional improvements include a security recommendations section in periodic reports, workflow module enhancements, and multiple UI and search optimisations.

The release also addresses CVE-2022-42724, a vulnerability that allowed organization-level administrators to discover role names that should only be visible to site administrators. While the impact is limited to information disclosure of role naming rather than data exposure or privilege escalation, the MISP project strongly recommends all administrators upgrade to this version. No evidence of active exploitation is mentioned in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2022-42724

Source reporting: https://www.misp-project.org/2022/10/10/misp.2.4.164.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/71009f72-3665-59cc-ab1a-b4a11d654636/misp-2-4-164-patches-org-admin-role-leak.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
