MISP 2.4.187 patches file upload flaws
MISP 2.4.187 fixes two file upload validation bugs (CVE-2024-29858, CVE-2024-29859) reported by Synacktiv, plus adds new CLI and OIDC features.
The MISP Project released version 2.4.187 of its open-source threat intelligence platform, addressing two security vulnerabilities related to improper file upload validation. CVE-2024-29858 affects the logo upload function in OrganisationsController.php, while CVE-2024-29859 affects the event export upload function in EventsController.php. Both issues were reported by researchers Rémi Matasse and Raphael Lob from Synacktiv.
Beyond the security fixes, the release includes CLI enhancements such as organization listing and user role management commands, an OIDC option to disable role changes from OIDC updates, and various dependency updates including PyMISP, misp-galaxy, misp-warninglists, misp-objects, and taxonomies. Additional bug fixes address sync pull failures, database compatibility with older MySQL versions, and API consistency issues.
This is a routine maintenance and security patch release for MISP administrators. Organizations running MISP instances below version 2.4.187 should upgrade to remediate the file upload validation weaknesses, which could potentially be leveraged to upload malicious files if left unpatched.
Mentioned in this report
Source reporting: https://www.misp-project.org/2024/03/24/misp.2.4.187.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free