# MISP 2.4.187 patches file upload flaws

Published: 2024-03-24 · Severity: medium
Canonical: https://vorant.io/reports/891595ae-e4be-578e-a93f-307481c1b8b9/misp-2-4-187-patches-file-upload-flaws

> MISP 2.4.187 fixes two file upload validation bugs (CVE-2024-29858, CVE-2024-29859) reported by Synacktiv, plus adds new CLI and OIDC features.

The MISP Project released version 2.4.187 of its open-source threat intelligence platform, addressing two security vulnerabilities related to improper file upload validation. CVE-2024-29858 affects the logo upload function in OrganisationsController.php, while CVE-2024-29859 affects the event export upload function in EventsController.php. Both issues were reported by researchers Rémi Matasse and Raphael Lob from Synacktiv.

Beyond the security fixes, the release includes CLI enhancements such as organization listing and user role management commands, an OIDC option to disable role changes from OIDC updates, and various dependency updates including PyMISP, misp-galaxy, misp-warninglists, misp-objects, and taxonomies. Additional bug fixes address sync pull failures, database compatibility with older MySQL versions, and API consistency issues.

This is a routine maintenance and security patch release for MISP administrators. Organizations running MISP instances below version 2.4.187 should upgrade to remediate the file upload validation weaknesses, which could potentially be leveraged to upload malicious files if left unpatched.

## Mentioned in this report

- Vulnerabilities: CVE-2024-29858, CVE-2024-29859

Source reporting: https://www.misp-project.org/2024/03/24/misp.2.4.187.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/891595ae-e4be-578e-a93f-307481c1b8b9/misp-2-4-187-patches-file-upload-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
