VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.123 patches two XSS flaws

routine vulnerability technology

MISP 2.4.123 fixes two XSS vulnerabilities found during a CCB-commissioned pentest and adds a new dashboard system.

MISP, the open-source threat intelligence sharing platform, released version 2.4.123 addressing two cross-site scripting vulnerabilities (CVE-2020-10246 and CVE-2020-10247) discovered during a penetration test conducted on behalf of the Centre for Cyber Security Belgium. The release also includes password policy improvements, additional preventative security headers, and better disclosure of suspicious activity to users.

Beyond the security fixes, the release introduces a new customizable Dashboard system built on a modular widget architecture, along with the ability to set custom landing pages and a fix for a bug causing correlations to disappear after certain attribute edits. No evidence of active exploitation of the XSS issues is mentioned; this is a routine maintenance and feature release with vendor-disclosed vulnerabilities.

Mentioned in this report

Vulnerabilities CVE-2020-10246CVE-2020-10247

Source reporting: https://www.misp-project.org/2020/03/10/misp.2.4.123.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free