VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.123 patches two XSS flaws

low vulnerability technology

MISP 2.4.123 fixes two XSS vulnerabilities found during a CCB-sponsored pentest and adds a new dashboard system.

MISP, the open-source threat intelligence sharing platform, released version 2.4.123 addressing two cross-site scripting vulnerabilities identified during a penetration test conducted on behalf of the Centre for Cyber Security Belgium (CCB). The vulnerabilities, tracked as CVE-2020-10246 and CVE-2020-10247, have been fixed, alongside broader security posture improvements including password policy enhancements, preventative security headers, and improved user notifications regarding suspicious activity.

The release also introduces a new customisable Dashboard system, developed partly in response to the MISP team's own efforts tracking COVID-19 spread via a Coronavirus-sharing community. The dashboard supports modular widgets, user-specific configurations, and shareable templates. Additionally, a bug causing correlations to disappear after certain attribute edits was identified and resolved, with a full recorrelation triggered on update.

This is a routine software update disclosing and patching low-severity web application vulnerabilities alongside feature enhancements; there is no indication of active exploitation.

Mentioned in this report

Vulnerabilities CVE-2020-10246CVE-2020-10247

Source reporting: https://www.misp-project.org/2020/03/10/misp.2.4.123.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free