Multiple Vulnerabilities in MISP
Multiple vulnerabilities in MISP allow a remote, authenticated attacker to perform privilege escalation to Site Administrator, bypass security controls, manipulate data, or execute cross-site scripting attacks.
The MISP Project has disclosed multiple vulnerabilities affecting MISP (Malware Information Sharing Platform). These flaws allow a remote, authenticated attacker to escalate privileges to the level of a Site Administrator, bypass existing security controls, perform unauthorized data manipulation, disclose sensitive information, or carry out stored and reflected Cross-Site Scripting (XSS) attacks. Given that MISP is frequently used to store highly sensitive threat intelligence, the potential impact of an account takeover or administrative compromise is significant, potentially granting an adversary visibility into an organization's entire threat research and response lifecycle. Defenders should review MISP instance logs for unusual administrative actions and ensure all instances are updated to the latest secure version provided by the project.
Impact
Successful exploitation of these vulnerabilities leads to unauthorized administrative access within the MISP platform. This facilitates the theft or modification of sensitive threat intelligence data, potential lateral movement through shared indicators, and the compromise of intelligence-sharing workflows. The breadth of data exposed depends on the specific MISP deployment and the sensitivity of the ingested threat feeds.
Recommendation
Prioritized, concrete actions for detection engineering and security operations teams:
- Update all MISP instances to the latest available version provided by the MISP Project immediately to mitigate the underlying vulnerabilities.
- Audit administrative log files in MISP for suspicious role changes or unauthorized configuration modifications.
- Implement strict session management and access controls for all MISP accounts, especially those with high-level privileges.
- Monitor web application logs for unusual URL patterns or request parameters that deviate from standard usage by authorized analysts.
Immediate actions
Upgrade all production MISP instances to the latest release.
Mitigations
Patch MISP to the latest stable version.
Multiple undisclosed MISP vulnerabilities