# MISP 2.4.140 patches sharing-group access flaw

Published: 2021-03-10 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/bac2eab0-19a2-5b33-858c-40246dfb958d/misp-2-4-140-patches-sharing-group-access-flaw

> MISP 2.4.140 fixes CVE-2021-27904, a Sharing Group access-control bug that could grant unintended view access, plus adds new features.

MISP, the open-source threat intelligence platform, released version 2.4.140 with a mix of feature additions and a security fix. New capabilities include OpenID Connect and Azure Active Directory authentication integrations, a built-in security audit tool for reviewing instance configuration and CSP posture, cross-referencing of objects across extended events, CLI improvements for server management and developer tooling, and new attribute types (full-name, dkim, dkim-signature) to support DKIM-related investigations.

The release also addresses a security vulnerability, CVE-2021-27904, discovered in app/Model/SharingGroupServer.php affecting MISP 2.4.139. The flaw relates to the Sharing Groups feature, where the "all org" flag could sometimes grant view access to organizations that should not have had it, potentially exposing shared threat intelligence data to unintended actors within a MISP community. The issue was reported by an external researcher and has been fixed in this release. Organizations running MISP instances with Sharing Groups configured should upgrade to 2.4.140 to prevent unauthorized data exposure.

## Mentioned in this report

- Vulnerabilities: CVE-2021-27904

Source reporting: https://www.misp-project.org/2021/03/10/misp.2.4.140.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bac2eab0-19a2-5b33-858c-40246dfb958d/misp-2-4-140-patches-sharing-group-access-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
