MISP 2.4.187 patches two upload flaws
MISP 2.4.187 fixes two file-upload validation vulnerabilities reported by Synacktiv along with new features and bug fixes.
The MISP Project released version 2.4.187 of its open-source threat intelligence platform, addressing two security vulnerabilities related to improper file upload validation. CVE-2024-29859 affects the add_misp_export function in EventsController.php, while CVE-2024-29858 affects the __uploadLogo function in OrganisationsController.php; both fail to properly validate uploaded files, which could allow malicious file uploads. The issues were reported by researchers Rémi Matasse and Raphael Lob from Synacktiv.
Beyond the security fixes, the release includes CLI enhancements, OIDC configuration options, updated dependencies (PyMISP, misp-galaxy, misp-warninglists, misp-objects, taxonomies), and various bug fixes including database compatibility improvements for older MySQL versions and sync reliability fixes. Organizations running MISP should update to 2.4.187 to remediate the disclosed vulnerabilities.
Mentioned in this report
Source reporting: https://www.misp-project.org/2024/03/24/misp.2.4.187.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free