# MISP 2.4.109 patches privilege escalation flaw

Published: 2019-06-14 · Severity: low
Canonical: https://vorant.io/reports/b67f5401-9026-574c-ada1-32990f70b721/misp-2-4-109-patches-privilege-escalation-flaw

> MISP 2.4.109 fixes CVE-2019-12794, a bug letting org admins reset or impersonate site admin credentials, plus adds new features.

MISP, the open-source threat intelligence platform, released version 2.4.109 addressing a privilege escalation vulnerability tracked as CVE-2019-12794. The flaw allowed organisation admins—who normally only manage users within their own organisation—to reset credentials for site admins or impersonate them by reusing their API keys. The issue only affects deployments where host organisations delegate lower-privilege organisation admin roles rather than granting full site admin access, but the project acknowledged it as a design flaw and issued a fix.

Beyond the security patch, the release introduces usability improvements including a feature to encapsulate loose attributes into structured MISP objects, and enhanced ATT&CK matrix visualization with aggregate scoring and filterable statistics based on community feedback from FIRST.org and Eurocontrol workshops. The API also gained a new restSearch date filter supporting flexible time-range syntax. MISP galaxy, object templates, and warning-lists were updated alongside the release.

This is a routine software update disclosure with a minor security fix rather than an actively exploited vulnerability. The project also flagged that the upcoming 2.4.110 release will involve significant data-model changes affecting time representation, requiring longer upgrade windows for larger instances.

## Mentioned in this report

- Vulnerabilities: CVE-2019-12794

Source reporting: https://www.misp-project.org/2019/06/14/misp.2.4.109.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b67f5401-9026-574c-ada1-32990f70b721/misp-2-4-109-patches-privilege-escalation-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
