# MISP 2.4.92 fixes two XSS vulnerabilities

Published: 2018-06-07 · Severity: low
Canonical: https://vorant.io/reports/d10ca1cc-2f63-5f5c-8716-8b94f36629e6/misp-2-4-92-fixes-two-xss-vulnerabilities

> MISP 2.4.92 patches two security vulnerabilities alongside performance improvements and STIX Python 3 migration.

MISP, the open-source threat intelligence sharing platform, released version 2.4.92 with a focus on performance optimization, particularly around the warning-lists feature used to detect false-positive attributes. The release also includes API improvements, ZMQ pub-sub role permissions, a rewritten flash messaging system, and the ability to hard-delete unpublished attributes to prevent sensitive data leakage via soft-deleted records.

Two security vulnerabilities, CVE-2018-11245 and CVE-2018-11562, were fixed in this release, reported by Jarek Kozluk and Dawid Czarnecki. No further technical detail on the vulnerabilities is provided in the article. Additionally, STIX 1 and STIX 2 export/import functionality was migrated to Python 3 with various format improvements, and PyMISP was updated with improved timestamp handling.

This is a routine software maintenance release for a widely used threat-intelligence platform; there is no indication of active exploitation of the fixed vulnerabilities.

## Mentioned in this report

- Vulnerabilities: CVE-2018-11245, CVE-2018-11562

Source reporting: https://www.misp-project.org/2018/06/07/misp.2.4.92.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d10ca1cc-2f63-5f5c-8716-8b94f36629e6/misp-2-4-92-fixes-two-xss-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
