VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.126 patches persistent XSS flaw

routine vulnerability technology

MISP 2.4.126 fixes a persistent XSS vulnerability (CVE-2020-13153) triggered via crafted attribute correlations in the freetext import tool.

MISP, the open-source threat intelligence sharing platform, released version 2.4.126 to address a persistent cross-site scripting vulnerability tracked as CVE-2020-13153. The flaw could be triggered when an attribute imported via the freetext import tool correlates with another attribute containing a JavaScript payload embedded in its comment field. When an analyst hovers over the resulting correlation, the malicious script would execute in their browser session, potentially allowing an attacker to compromise the analyst's session or manipulate the platform.

Beyond the security fix, the release adds a tool to generate a communities webpage to help users find relevant MISP communities, an experimental CLI-only force-pull method for administrators to forcibly synchronize local instances with remote data (intended as a last-resort recovery option), and a broad set of quality-of-life improvements alongside updates to misp-objects, misp-taxonomies, and misp-galaxy. There is no indication of active exploitation; this is a routine maintenance and security patch release for platform operators to apply.

Mentioned in this report

Vulnerabilities CVE-2020-13153

Source reporting: https://www.misp-project.org/2020/06/04/misp.2.4.126.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free