MISP 2.4.167 patches XSS flaw CVE-2022-47928
MISP released version 2.4.167, fixing an XSS vulnerability (CVE-2022-47928) alongside new features like timeline improvements and free-text object creation.
The MISP project released version 2.4.167, addressing a cross-site scripting (XSS) vulnerability tracked as CVE-2022-47928. Users are advised to upgrade to the latest version to remediate the issue. Alongside the security fix, the release introduces several usability enhancements including improved timeline visualization for large events, taxonomy highlighting for site admins, the ability to create MISP objects directly from free-text import, and a new API session kill-switch endpoint developed for the MeliCERTes project.
The update also includes additions to MISP's galaxy and object libraries, such as new threat-actor entries (TAG-53, Malteiro, and others), updates to RAT and ransomware group galaxies, and new object templates including thaicert-group-cards and Palantir ADS. A new aviation taxonomy was contributed by the European Air Traffic Management CERT. This is a routine platform maintenance release for the MISP threat intelligence sharing platform, with no indication of active exploitation of the XSS vulnerability in the wild.
Mentioned in this report
Source reporting: https://www.misp-project.org/2022/12/26/misp.2.4.167.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free