MISP 2.4.123 patches two XSS flaws
MISP 2.4.123 fixes two XSS vulnerabilities found during a CCB-sponsored pentest and adds a new dashboard system.
MISP, the open-source threat intelligence sharing platform, released version 2.4.123 addressing two cross-site scripting vulnerabilities identified during a penetration test conducted on behalf of the Centre for Cyber Security Belgium (CCB). The vulnerabilities, tracked as CVE-2020-10246 and CVE-2020-10247, have been fixed, alongside broader security posture improvements including password policy enhancements, preventative security headers, and improved user notifications regarding suspicious activity.
The release also introduces a new customisable Dashboard system, developed partly in response to the MISP team's own efforts tracking COVID-19 spread via a Coronavirus-sharing community. The dashboard supports modular widgets, user-specific configurations, and shareable templates. Additionally, a bug causing correlations to disappear after certain attribute edits was identified and resolved, with a full recorrelation triggered on update.
This is a routine software update disclosing and patching low-severity web application vulnerabilities alongside feature enhancements; there is no indication of active exploitation.
Mentioned in this report
Source reporting: https://www.misp-project.org/2020/03/10/misp.2.4.123.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free