MISP 2.4.121 patches five vulnerabilities
MISP 2.4.121 fixes five vulnerabilities including a reflected XSS and multiple brute-force protection bypasses.
The MISP threat-intelligence platform project released version 2.4.121, a security and bug-fix release addressing five vulnerabilities reported by researcher Dawid Czarnecki. The issues include a reflected cross-site scripting flaw in the galaxy view (CVE-2020-8893), an access-control list bypass affecting discussion threads (CVE-2020-8894), and a set of brute-force protection weaknesses. The brute-force issues stem from potential time skew between the web server and database causing the protection to not trigger (CVE-2020-8890), missing username canonicalization before logging bruteforce entries (CVE-2020-8891), and PUT requests on the login endpoint bypassing the protection entirely (CVE-2020-8892).
The project states none of the vulnerabilities are deemed critical, but strongly recommends users update and inform peers to do the same. Alongside the security fixes, the release adds new sync pull filters to limit unfiltered flow of aged-out data during initial community synchronization, corrects background worker configuration loading behavior, improves memory envelope estimation for large datasets, and enhances SQL schema check diagnostics. Several new MISP object templates were also added covering disinformation, media, and improved HTTP representation use cases.
This is a routine maintenance and security patch release for MISP administrators rather than an actively exploited threat, warranting prompt but non-urgent patching.
Mentioned in this report
Source reporting: https://www.misp-project.org/2020/02/12/misp.2.4.121.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free