VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.110 fixes admin RCE flaw

routine vulnerability

MISP 2.4.110 patches CVE-2019-12868, a PHP deserialization bug allowing remote code execution by a site super admin, plus adds new features and fixes.

The MISP project released version 2.4.110, a maintenance and feature update to the open-source threat intelligence sharing platform. Alongside new capabilities such as expanded misp-modules support for the full MISP standard format, local tagging, and a Norwegian translation, the release addresses a security vulnerability tracked as CVE-2019-12868.

The flaw affected MISP 2.4.109 and stemmed from unsafe use of PHP's file_exists function with user-controlled input, where phar:// URLs could trigger PHP object deserialization leading to remote command execution. Exploitation required site administrator privileges, limiting the practical attack surface to a malicious or compromised super admin account rather than an unauthenticated remote attacker. The issue was reported by Dawid Czarnecki and has been resolved in this release along with several STIX export/import parsing fixes.

Organizations running MISP instances should upgrade to 2.4.110 to remediate the deserialization vulnerability, though the requirement for existing admin-level access reduces the urgency compared to unauthenticated RCE issues. The release also includes numerous quality-of-life and API improvements contributed by the community and partners such as Siemens and SANS.

Mentioned in this report

Vulnerabilities CVE-2019-12868

Source reporting: https://www.misp-project.org/2019/07/08/misp.2.4.110.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free