VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.103 patches sighting visibility flaw

low vulnerability technology

MISP 2.4.103 fixes CVE-2019-9482, a bug allowing authenticated users to view sightings they shouldn't have access to.

MISP released version 2.4.103, primarily a feature and UI update introducing an improved attribute filtering tool, generic matrix-like galaxy support for MITRE ATT&CK-style models, and various API and enhancement additions. Alongside these improvements, the release addresses a security vulnerability tracked as CVE-2019-9482.

The vulnerability affected MISP 2.4.102 and earlier, where an authenticated user could view sightings they should not have had access to. Exploitation required the attacker to have access to the event that received the sighting, combined with restrictive sighting visibility settings (event-only or sighting-reported-only configurations). The issue was reported by Tyler McLellan of CanCyber.org and has been resolved in this release. Given the vulnerability requires authenticated access and specific configuration conditions, the real-world risk is limited to information disclosure within an organization's own MISP instance rather than external compromise.

Mentioned in this report

Vulnerabilities CVE-2019-9482

Source reporting: https://www.misp-project.org/2019/03/04/misp.2.4.103.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free