# MISP 2.4.167 patches XSS flaw CVE-2022-47928

Published: 2022-12-26 · Severity: medium
Canonical: https://vorant.io/reports/e461d583-bbc7-5f09-bbf3-a80491af1256/misp-2-4-167-patches-xss-flaw-cve-2022-47928

> MISP released version 2.4.167, fixing an XSS vulnerability (CVE-2022-47928) alongside new features like timeline improvements and free-text object creation.

The MISP project released version 2.4.167, addressing a cross-site scripting (XSS) vulnerability tracked as CVE-2022-47928. Users are advised to upgrade to the latest version to remediate the issue. Alongside the security fix, the release introduces several usability enhancements including improved timeline visualization for large events, taxonomy highlighting for site admins, the ability to create MISP objects directly from free-text import, and a new API session kill-switch endpoint developed for the MeliCERTes project.

The update also includes additions to MISP's galaxy and object libraries, such as new threat-actor entries (TAG-53, Malteiro, and others), updates to RAT and ransomware group galaxies, and new object templates including thaicert-group-cards and Palantir ADS. A new aviation taxonomy was contributed by the European Air Traffic Management CERT. This is a routine platform maintenance release for the MISP threat intelligence sharing platform, with no indication of active exploitation of the XSS vulnerability in the wild.

## Mentioned in this report

- Vulnerabilities: CVE-2022-47928
- Threat actors: Malteiro, TAG-53

Source reporting: https://www.misp-project.org/2022/12/26/misp.2.4.167.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e461d583-bbc7-5f09-bbf3-a80491af1256/misp-2-4-167-patches-xss-flaw-cve-2022-47928.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
