# MISP 2.4.103 patches sighting visibility flaw

Published: 2019-03-04 · Severity: low · Sectors: technology
Canonical: https://vorant.io/reports/f9ae5318-892f-5ad8-8118-f4dc4515cfbf/misp-2-4-103-patches-sighting-visibility-flaw

> MISP 2.4.103 fixes CVE-2019-9482, a bug allowing authenticated users to view sightings they shouldn't have access to.

MISP released version 2.4.103, primarily a feature and UI update introducing an improved attribute filtering tool, generic matrix-like galaxy support for MITRE ATT&CK-style models, and various API and enhancement additions. Alongside these improvements, the release addresses a security vulnerability tracked as CVE-2019-9482.

The vulnerability affected MISP 2.4.102 and earlier, where an authenticated user could view sightings they should not have had access to. Exploitation required the attacker to have access to the event that received the sighting, combined with restrictive sighting visibility settings (event-only or sighting-reported-only configurations). The issue was reported by Tyler McLellan of CanCyber.org and has been resolved in this release. Given the vulnerability requires authenticated access and specific configuration conditions, the real-world risk is limited to information disclosure within an organization's own MISP instance rather than external compromise.

## Mentioned in this report

- Vulnerabilities: CVE-2019-9482

Source reporting: https://www.misp-project.org/2019/03/04/misp.2.4.103.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f9ae5318-892f-5ad8-8118-f4dc4515cfbf/misp-2-4-103-patches-sighting-visibility-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
