# MISP 2.4.89 patches two security bugs

Published: 2018-03-23 · Severity: low
Canonical: https://vorant.io/reports/e34e5e84-a410-5ebb-af9d-b05e70c3cbad/misp-2-4-89-patches-two-security-bugs

> MISP 2.4.89 fixes an XSS flaw in misp-modules and an API integrity bug allowing attribute overwrite, alongside new event graph and STIX 2.0 features.

The MISP threat-sharing platform released version 2.4.89, addressing two security vulnerabilities alongside a batch of feature updates. CVE-2018-8948 concerns improper sanitisation from misp-modules, which could allow cross-site scripting via malicious expansion modules. CVE-2018-8949 is an API integrity issue where an authenticated user could edit or overwrite an attribute lacking a UUID, bypassing expected access controls.

Beyond the security fixes, the release adds a graphical event graph viewer/editor for objects, attributes, and relationships, STIX 2.0 import support in addition to existing export capability, and various API improvements including UUID exposure in attribute-level restSearch and mass-delete for attributes. A separate non-CVE bug affecting the object handler, which could allow objects to be overwritten under specific conditions, was also remediated with a new diagnostics recovery tool.

This is a routine software maintenance release for a widely used open-source threat intelligence platform; the vulnerabilities are low-severity and require authenticated access or reliance on malicious third-party modules, with no indication of active exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2018-8948, CVE-2018-8949

Source reporting: https://www.misp-project.org/2018/03/23/misp.2.4.89.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e34e5e84-a410-5ebb-af9d-b05e70c3cbad/misp-2-4-89-patches-two-security-bugs.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
