MISP 2.4.109 patches privilege-escalation flaw
MISP 2.4.109 fixes CVE-2019-12794, letting org admins reset or impersonate site admin credentials via API key reuse.
The MISP threat-sharing platform released version 2.4.109, primarily a feature and bugfix update that also addresses a privilege-escalation vulnerability tracked as CVE-2019-12794. The flaw allowed organisation-level admins, who already have the ability to reset passwords for users within their own organisation, to reset credentials for site-wide admins or impersonate them by reusing their API keys. Exploitation requires a specific deployment pattern where the hosting organisation assigns lower-privilege organisation admins rather than full site admins, limiting real-world exposure but still representing a design weakness in the permission model.
Beyond the security fix, the release introduces usability improvements such as encapsulating loose attributes into structured objects and enhanced ATT&CK matrix visualization with time-range and organisation-based filtering. A new restSearch API filter for date-based queries was also added, along with various permission and UI bug fixes. The MISP project advises all users to upgrade, and flags that the subsequent 2.4.110 release will involve a more disruptive database schema migration.
Mentioned in this report
Source reporting: https://www.misp-project.org/2019/06/14/misp.2.4.109.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free