VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.109 patches privilege-escalation flaw

routine vulnerability

MISP 2.4.109 fixes CVE-2019-12794, letting org admins reset or impersonate site admin credentials via API key reuse.

The MISP threat-sharing platform released version 2.4.109, primarily a feature and bugfix update that also addresses a privilege-escalation vulnerability tracked as CVE-2019-12794. The flaw allowed organisation-level admins, who already have the ability to reset passwords for users within their own organisation, to reset credentials for site-wide admins or impersonate them by reusing their API keys. Exploitation requires a specific deployment pattern where the hosting organisation assigns lower-privilege organisation admins rather than full site admins, limiting real-world exposure but still representing a design weakness in the permission model.

Beyond the security fix, the release introduces usability improvements such as encapsulating loose attributes into structured objects and enhanced ATT&CK matrix visualization with time-range and organisation-based filtering. A new restSearch API filter for date-based queries was also added, along with various permission and UI bug fixes. The MISP project advises all users to upgrade, and flags that the subsequent 2.4.110 release will involve a more disruptive database schema migration.

Mentioned in this report

Vulnerabilities CVE-2019-12794

Source reporting: https://www.misp-project.org/2019/06/14/misp.2.4.109.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free