VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.140 fixes sharing-group access flaw

medium vulnerability technology

MISP 2.4.140 patches CVE-2021-27904, a sharing-group access control flaw, alongside new features and CLI improvements.

The MISP threat-intelligence platform released version 2.4.140, addressing a vulnerability in its Sharing Groups implementation. The flaw, found in app/Model/SharingGroupServer.php, caused the "all org" flag to sometimes grant unintended view access to organizations that should not have had it, potentially exposing sensitive shared threat data to unauthorized actors. The issue was reported by Jeroen Pinoy and assigned CVE-2021-27904.

Beyond the security fix, the release adds several new capabilities including OpenID Connect and Azure Active Directory authentication integrations, a built-in security audit tool for reviewing instance configuration and CSP posture, and the ability to cross-reference objects across extended events for building connected data graphs. CLI tooling was also expanded to support server listing, sync automation, and developer workflows, and new attribute types (full-name, dkim, dkim-signature) were added to support DKIM-related investigations.

This is a routine software update advisory for a widely used open-source threat intelligence sharing platform. There is no indication of active exploitation of the disclosed vulnerability; it is a responsibly disclosed access-control bug fixed in the same release cycle as feature improvements.

Mentioned in this report

Vulnerabilities CVE-2021-27904

Source reporting: https://www.misp-project.org/2021/03/10/misp.2.4.140.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free