MISP 2.4.168 patches four XSS/ACL flaws
MISP 2.4.168 fixes three XSS vulnerabilities and one access-control flaw in the decaying import function.
The MISP project released version 2.4.168, addressing four security issues alongside general bug fixes and a substantial update to the misp-stix library. Three of the vulnerabilities (CVE-2023-24070, CVE-2023-24026, CVE-2023-24027) are cross-site scripting flaws affecting the AuthKeys display view, the event-graph preview feature, and the network history action table, respectively. A fourth issue, CVE-2023-24028, involves incorrect access control in the ACLComponent governing the decaying import function, potentially allowing unauthorized access to that feature.
The vulnerabilities were reported by Cyber Controls from SIX Group and Dawid Czarnecki of Zigrin Security. No evidence of active exploitation is mentioned; this is a routine maintenance and security patch release for the open-source threat intelligence platform. Organizations running MISP versions prior to 2.4.168 should upgrade to remediate these XSS and access-control weaknesses. The release also includes non-security improvements such as new MISP objects, galaxy updates for threat actors and ransomware, and warning-list generator fixes.
Mentioned in this report
Source reporting: https://www.misp-project.org/2023/02/16/misp.2.4.168.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free