VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.126 patches persistent XSS flaw

medium vulnerability technology

MISP 2.4.126 fixes a persistent XSS vulnerability (CVE-2020-13153) triggered via correlated attributes in the freetext import tool.

MISP, the open-source threat intelligence sharing platform, released version 2.4.126, addressing a persistent cross-site scripting vulnerability tracked as CVE-2020-13153. The flaw could be triggered when an analyst uses the freetext import tool to correlate an attribute containing a JavaScript payload embedded in the comment field; simply hovering over the resulting correlation in the UI would execute the malicious script in the analyst's browser session.

The vulnerability was reported by a researcher and fixed in this release alongside several quality-of-life improvements, including a communities webpage generation tool and an experimental CLI-only force-pull method for administrators to override local modifications with remote data. The update also bundles refreshed misp-objects, misp-taxonomies, and misp-galaxy content. No evidence of active exploitation is mentioned; this is a routine maintenance and security patch release.

Mentioned in this report

Vulnerabilities CVE-2020-13153

Source reporting: https://www.misp-project.org/2020/06/04/misp.2.4.126.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free