VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.142 patches sharing-group flaw

medium vulnerability

MISP 2.4.142 fixes CVE-2021-31780, a bug that could misalign sharing groups on synced attributes, alongside correlation and UI improvements.

The MISP project released version 2.4.142, addressing a security issue tracked as CVE-2021-31780 that could cause sharing groups to become misaligned on synced attributes between MISP instances. This could potentially expose shared threat intelligence data to unintended audiences within federated MISP communities, so the project urges all users to update.

Beyond the security fix, the release introduces correlation exclusion tooling to reduce noise from low-quality correlations (e.g., empty hashes, default registry values), a reworked server sync rule management UI, new dashboard widgets for usage monitoring, and updates to misp-objects, misp-taxonomies, and misp-galaxy, including a major expansion of the Ransomware galaxy to over 1600 documented families.

Mentioned in this report

Vulnerabilities CVE-2021-31780

Source reporting: https://www.misp-project.org/2021/04/27/misp.2.4.142.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free