MISP 2.4.142 patches sharing group flaw
MISP 2.4.142 fixes CVE-2021-31780, a bug that could misalign sharing groups on synced attributes, plus adds correlation and sync management improvements.
The MISP project released version 2.4.142, addressing a security issue tracked as CVE-2021-31780 that could cause sharing groups on synced attributes to become misaligned, potentially exposing shared threat data to unintended audiences. The advisory urges all MISP instance administrators to update to remediate the issue.
Beyond the security fix, the release introduces several usability improvements aimed at reducing noisy or low-quality correlations, including a new correlation exclusion list and a 'top correlations' view to identify and prune problematic data points. Server sync rule management was also reworked with a friendlier UI and automatic tag retrieval for pull filters. The release further includes new dashboard widgets for usage statistics and updates to misp-objects, misp-taxonomies, and misp-galaxy, notably expanding the Ransomware galaxy to over 1600 documented ransomware families.
Mentioned in this report
Source reporting: https://www.misp-project.org/2021/04/27/misp.2.4.142.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free