# MISP 2.4.187 patches two upload flaws

Published: 2024-03-24 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/891595ae-e4be-578e-a93f-307481c1b8b9/misp-2-4-187-patches-two-upload-flaws

> MISP 2.4.187 fixes two file-upload validation vulnerabilities reported by Synacktiv along with new features and bug fixes.

The MISP Project released version 2.4.187 of its open-source threat intelligence platform, addressing two security vulnerabilities related to improper file upload validation. CVE-2024-29859 affects the add_misp_export function in EventsController.php, while CVE-2024-29858 affects the __uploadLogo function in OrganisationsController.php; both fail to properly validate uploaded files, which could allow malicious file uploads. The issues were reported by researchers Rémi Matasse and Raphael Lob from Synacktiv.

Beyond the security fixes, the release includes CLI enhancements, OIDC configuration options, updated dependencies (PyMISP, misp-galaxy, misp-warninglists, misp-objects, taxonomies), and various bug fixes including database compatibility improvements for older MySQL versions and sync reliability fixes. Organizations running MISP should update to 2.4.187 to remediate the disclosed vulnerabilities.

## Mentioned in this report

- Vulnerabilities: CVE-2024-29858, CVE-2024-29859

Source reporting: https://www.misp-project.org/2024/03/24/misp.2.4.187.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/891595ae-e4be-578e-a93f-307481c1b8b9/misp-2-4-187-patches-two-upload-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
