MISP 2.4.147 patches CVE-2021-37534
MISP released version 2.4.147, fixing a security vulnerability (CVE-2021-37534) along with numerous sync and API improvements.
The MISP project released version 2.4.147 of its open-source threat intelligence sharing platform. The release addresses CVE-2021-37534 alongside a broad set of bug fixes and improvements, particularly in event synchronisation logic (sighting deduplication, event existence checks before push, and filtering optimisations) and in the API/CLI layer.
No details on exploitation, exploit availability, or affected components are provided in the announcement beyond the CVE reference. The release also bundles updates to misp-objects, misp-taxonomies, and misp-galaxy. This is a routine maintenance release; the project recommends all users upgrade.
Mentioned in this report
Source reporting: https://www.misp-project.org/2021/07/27/misp.2.4.147.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free