# MISP 2.4.198 patches info-disclosure flaw

Published: 2024-09-17 · Severity: medium · Sectors: government-national
Canonical: https://vorant.io/reports/da1771b2-c305-5f5f-a7e6-e54993eb152f/misp-2-4-198-patches-info-disclosure-flaw

> MISP 2.4.198 fixes a vulnerability (CVE-2024-45509) that let org-admins view sensitive login-profile fields of other org-admins, plus an ACL bypass in attribute search.

MISP released version 2.4.198 to address a security issue tracked as CVE-2024-45509, in which insufficient sanitization of sensitive fields in user-login-profiles allowed org-admins to view sensitive data belonging to other org-admins within the same organization during login session confirmation. The issue was reported by Sharad Kumar Dahal of Green Tick Nepal Pvt. Ltd.

The release also addresses a separate, as-yet unassigned vulnerability where access control lists (ACLs) were ignored on the GUI attribute search, reported by KZ-CERT, the National CERT Team of Kazakhstan. Additional fixes cover authkey visibility redaction between org-admins, attribute search return errors, and several internal/UI improvements, including a new dom-hash attribute type for fingerprinting HTML DOM structures to support correlation of phishing pages via tools like LookyLoo.

This is a routine maintenance and security release for an open-source threat-intelligence platform widely used by CERTs and security teams. Users are advised to update promptly given the disclosed vulnerabilities involve privilege and access-control issues, though no active exploitation is reported.

## Mentioned in this report

- Vulnerabilities: CVE-2024-45509

Source reporting: https://www.misp-project.org/2024/09/17/misp.2.4.198.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/da1771b2-c305-5f5f-a7e6-e54993eb152f/misp-2-4-198-patches-info-disclosure-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
