MISP 2.4.147 Patches CVE-2021-37534
MISP released version 2.4.147 with sync, API, and CLI improvements plus a fix for security flaw CVE-2021-37534.
The MISP project shipped version 2.4.147, a maintenance release addressing a large number of bug fixes and small improvements alongside a specific security fix tracked as CVE-2021-37534. Notable changes include several synchronisation optimisations—such as only pushing new sightings, filtering existing sightings when supported by the remote server, and checking for event existence before pushing data—intended to reduce redundant traffic and improve reliability between MISP instances.
The release also refactors portions of the API, CLI, and various forms to lay groundwork for future major improvements, and bundles updates to the misp-objects, misp-taxonomies, and misp-galaxy components. No indication of active exploitation of CVE-2021-37534 is provided in the release notes; this is a routine vendor patch advisory recommending users upgrade as a precaution.
Mentioned in this report
Source reporting: https://www.misp-project.org/2021/07/27/misp.2.4.147.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free