# MISP 2.4.198 fixes info-disclosure bugs

Published: 2024-09-17 · Severity: low
Canonical: https://vorant.io/reports/da1771b2-c305-5f5f-a7e6-e54993eb152f/misp-2-4-198-fixes-info-disclosure-bugs

> MISP 2.4.198 patches an org-admin login-profile data exposure (CVE-2024-45509) and a GUI attribute search ACL bypass reported by KZ-CERT.

The MISP project released version 2.4.198 to address a security issue where sensitive fields in user-login-profiles could be viewed by other org-admins within the same organization during login session confirmation. This flaw has been assigned CVE-2024-45509 and was reported by Sharad Kumar Dahal of Green Tick Nepal Pvt. Ltd. The release also fixes a separate access-control issue where the GUI attribute search did not properly enforce ACLs, reported by KZ-CERT (Kazakhstan's national CERT); a CVE for this second issue is pending allocation.

Beyond the security fixes, the release adds a new dom-hash attribute type for fingerprinting HTML DOM structure (useful for correlating phishing pages, as implemented in tools like LookyLoo), along with several internal fixes to attribute search, user role visibility, and baseline URL preference handling. There is no indication of active exploitation; this is a routine maintenance and security-hardening release for the MISP threat-intelligence sharing platform, and administrators are encouraged to update promptly.

## Mentioned in this report

- Vulnerabilities: CVE-2024-45509

Source reporting: https://www.misp-project.org/2024/09/17/misp.2.4.198.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/da1771b2-c305-5f5f-a7e6-e54993eb152f/misp-2-4-198-fixes-info-disclosure-bugs.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
