# MISP 2.4.164 patches role-name disclosure flaw

Published: 2022-10-10 · Severity: low
Canonical: https://vorant.io/reports/71009f72-3665-59cc-ab1a-b4a11d654636/misp-2-4-164-patches-role-name-disclosure-flaw

> MISP released version 2.4.164, fixing CVE-2022-42724 where org admins could discover restricted role names, plus new tag relationship features.

The MISP threat-sharing platform project released version 2.4.164, addressing a low-severity access control vulnerability tracked as CVE-2022-42724. The flaw allowed organization-level administrators to enumerate role names that should only be visible to site administrators, a minor information disclosure issue rather than a path to privilege escalation or data compromise.

Alongside the security fix, the release introduces a new tag relationship feature allowing relationships to be added to attribute or event tags and galaxy clusters, exposed via a new API endpoint. Additional improvements include a security recommendations section in periodic reports tied to attack techniques, workflow enhancements, expanded API filtering for galaxy cluster searches, and UI optimizations. MISP administrators are advised to upgrade to this version to remediate the disclosed vulnerability.

## Mentioned in this report

- Vulnerabilities: CVE-2022-42724

Source reporting: https://www.misp-project.org/2022/10/10/misp.2.4.164.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/71009f72-3665-59cc-ab1a-b4a11d654636/misp-2-4-164-patches-role-name-disclosure-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
