VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.168 patches four XSS/ACL flaws

medium vulnerability technology

MISP 2.4.168 fixes three XSS vulnerabilities and one access-control flaw in the decaying import function.

The MISP project released version 2.4.168, addressing four security issues alongside general bug fixes and a substantial update to the misp-stix library. Three of the vulnerabilities (CVE-2023-24070, CVE-2023-24026, CVE-2023-24027) are cross-site scripting flaws affecting the AuthKeys display view, the event-graph preview feature, and the network history action table, respectively. A fourth issue, CVE-2023-24028, involves incorrect access control in the ACLComponent governing the decaying import function, potentially allowing unauthorized access to that feature.

The vulnerabilities were reported by Cyber Controls from SIX Group and Dawid Czarnecki of Zigrin Security. No evidence of active exploitation is mentioned; this is a routine maintenance and security patch release for the open-source threat intelligence platform. Organizations running MISP versions prior to 2.4.168 should upgrade to remediate these XSS and access-control weaknesses. The release also includes non-security improvements such as new MISP objects, galaxy updates for threat actors and ransomware, and warning-list generator fixes.

Mentioned in this report

Vulnerabilities CVE-2023-24026CVE-2023-24027CVE-2023-24028CVE-2023-24070

Source reporting: https://www.misp-project.org/2023/02/16/misp.2.4.168.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free