# MISP 2.4.168 fixes multiple XSS flaws

Published: 2023-02-16 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/9dbcf373-aba2-552c-9bfd-a58f4e4be38b/misp-2-4-168-fixes-multiple-xss-flaws

> MISP released version 2.4.168 patching three XSS vulnerabilities and an access control flaw in the threat-intel platform.

The MISP project released version 2.4.168, addressing four security vulnerabilities alongside bug fixes and library improvements. Three of the flaws (CVE-2023-24070, CVE-2023-24026, CVE-2023-24027) are cross-site scripting issues affecting the AuthKeys display, event-graph preview, and network history name components. The fourth, CVE-2023-24028, is an access control weakness in the ACLComponent affecting the decaying import function.

These vulnerabilities were reported by researchers from SIX Group and Zigrin Security and were responsibly disclosed and fixed in this release. The update also includes broader improvements to MISP objects, galaxies, taxonomies, and warning-lists, but the security-relevant content is limited to the four CVEs. There is no indication of active exploitation in the wild; this is a routine maintenance and security patch release for a widely used open-source threat intelligence sharing platform.

## Mentioned in this report

- Vulnerabilities: CVE-2023-24026, CVE-2023-24027, CVE-2023-24028, CVE-2023-24070

Source reporting: https://www.misp-project.org/2023/02/16/misp.2.4.168.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9dbcf373-aba2-552c-9bfd-a58f4e4be38b/misp-2-4-168-fixes-multiple-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
