VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.167 patches XSS flaw CVE-2022-47928

routine vulnerability

MISP released version 2.4.167, fixing an XSS vulnerability (CVE-2022-47928) alongside new UI and timeline features.

The MISP project released version 2.4.167, addressing a cross-site scripting (XSS) vulnerability tracked as CVE-2022-47928. The advisory recommends all users upgrade to the latest version to mitigate the flaw. No details on active exploitation were provided, and the issue appears to be a routine software vulnerability disclosure rather than an in-the-wild threat.

Beyond the security fix, the release introduces several usability improvements including enhanced timeline visualization for large events, taxonomy highlighting for site administrators, the ability to create objects directly from free-text import, and a new API session kill-switch for MeliCERTes integration. The update also added new threat-actor galaxy entries (e.g., TAG-53, Malteiro), updated RAT and ransomware group data, and new object templates, reflecting ongoing maintenance of the platform's threat intelligence data model rather than any new threat activity.

Mentioned in this report

Vulnerabilities CVE-2022-47928

Source reporting: https://www.misp-project.org/2022/12/26/misp.2.4.167.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free