VORANT. Threat Intelligence Sign in Get the full feed

MISP patches CSRF-like event deletion bug

low vulnerability technology

MISP 2.4.132 fixes CVE-2020-25766, a bug that could trigger unintended event deletions under certain session conditions.

MISP (Malware Information Sharing Platform) released version 2.4.132, addressing several bug fixes and one notable security issue tracked as CVE-2020-25766. The flaw stemmed from a login form GET/POST exchange bug combined with session/pagination handling: under resource exhaustion conditions, a user with a valid session could be shown the login page instead of the expected view, and a subsequent form submission (intended as an event deletion action) could be inadvertently triggered against the event index instead of the intended target.

The MISP team stated this scenario is extremely rare in practice and only a handful of such unintended deletions were identified on their most heavily used community instances. A follow-up release (2.4.133) is planned to include a diagnostic tool to identify deletions that occurred during the window the bug was active, along with recovery functionality. The release also includes unrelated fixes such as a bootstrap-datepicker update, tag filter corrections, and a new sightings anonymisation setting.

Mentioned in this report

Vulnerabilities CVE-2020-25766

Source reporting: https://www.misp-project.org/2020/09/21/misp.2.4.132.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free