VORANT. Threat Intelligence Sign in Get the full feed

MISP patches two authenticated SQLi flaws

elevated vulnerability

MISP fixed two SQL injection vulnerabilities allowing authenticated users to run arbitrary SQL queries, patched silently in v2.4.166 and v2.4.167.

MISP, the open-source threat intelligence sharing platform, disclosed two separate SQL injection vulnerabilities discovered over a two-month period ending December 2022. Both flaws allowed any authenticated user to execute arbitrary SQL queries against the underlying database: one stemmed from unsafe use of CakePHP's find() order parameter in custom field sorting on endpoints like RestSearch, and the other from unsanitized field names accepted by the CRUD component's search functionality, despite the search values themselves being properly sanitized.

The MISP team opted for a silent-fix approach, disguising the patches as minor refactors and bug fixes while working directly with the reporters, then later drawing community attention to unrelated minor issues to encourage upgrades without publicly signaling the true severity of the SQLi bugs. This is described as an approach reserved for extreme cases to give the user community time to patch before public disclosure. The first vulnerability (CVE-2022-48329) was reported by Jakub Onderka on 2022/11/25 and fixed in v2.4.166 on 2022/11/28. The second (CVE-2022-48328) was reported by Dawid Czarnecki of Zigrin Security on 2022/12/12 and fixed in v2.4.167 on 2022/12/22.

Both issues have been remediated through field allow-listing and are fixed in current releases. No evidence of active exploitation is mentioned; this is a vulnerability disclosure and patch advisory rather than an in-the-wild attack report. Organizations running MISP should ensure they are on v2.4.167 or later.

Mentioned in this report

Vulnerabilities CVE-2022-48328CVE-2022-48329

Source reporting: https://www.misp-project.org/2023/02/20/critical_sql_injection_vulnerabilities_fixed.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free