VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.167 patches XSS flaw CVE-2022-47928

medium threat

MISP released version 2.4.167, fixing an XSS vulnerability (CVE-2022-47928) alongside new features like timeline improvements and free-text object creation.

The MISP project released version 2.4.167, addressing a cross-site scripting (XSS) vulnerability tracked as CVE-2022-47928. Users are advised to upgrade to the latest version to remediate the issue. Alongside the security fix, the release introduces several usability enhancements including improved timeline visualization for large events, taxonomy highlighting for site admins, the ability to create MISP objects directly from free-text import, and a new API session kill-switch endpoint developed for the MeliCERTes project.

The update also includes additions to MISP's galaxy and object libraries, such as new threat-actor entries (TAG-53, Malteiro, and others), updates to RAT and ransomware group galaxies, and new object templates including thaicert-group-cards and Palantir ADS. A new aviation taxonomy was contributed by the European Air Traffic Management CERT. This is a routine platform maintenance release for the MISP threat intelligence sharing platform, with no indication of active exploitation of the XSS vulnerability in the wild.

Mentioned in this report

Vulnerabilities CVE-2022-47928
Threat actors MalteiroTAG-53

Source reporting: https://www.misp-project.org/2022/12/26/misp.2.4.167.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free