# MISP patches accidental event-deletion flaw

Published: 2020-09-21 · Severity: low
Canonical: https://vorant.io/reports/b2f49c21-24a9-5a7c-a2ab-65d716ee16bd/misp-patches-accidental-event-deletion-flaw

> MISP 2.4.132 fixes CVE-2020-25766, a bug that could trigger unintended event deletions under session exhaustion.

The MISP threat-sharing platform released version 2.4.132, addressing several bugs including a notable security issue tracked as CVE-2020-25766. The flaw arose from an edge case where, under resource exhaustion (such as heavy session data retrieval), a paginated event view could incorrectly serve the login page instead of the expected content. A bug in the login form's GET/POST handling meant that a user with a valid session would then have their credentials resubmit the prior form on the event index page, which in some cases was an event deletion request, resulting in unintended data loss.

MISP maintainers noted this was extremely rare in practice, having identified only a handful of such incidents even on heavily used community instances. The issue was reported by Michael Kerscher. Alongside the security fix, the release includes several other bug fixes such as correcting tag filter handling for OR conditions and non-admin users, updating bootstrap-datepicker, and adding a sightings anonymization setting. A follow-up release, version 2.4.133, is planned to include a diagnostic tool to identify deletions caused by this bug and a recovery mechanism.

## Mentioned in this report

- Vulnerabilities: CVE-2020-25766

Source reporting: https://www.misp-project.org/2020/09/21/misp.2.4.132.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b2f49c21-24a9-5a7c-a2ab-65d716ee16bd/misp-patches-accidental-event-deletion-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
