Full Report
MISP security advisory (AV26-986)
Analysis Summary
# Vulnerability: Multiple Security Flaws in MISP (Malware Information Sharing Platform)
## CVE Details
- **CVE ID:** CVE-Not-Explicitly-Stated (Advisory AV26-986 refers to a collection of security fixes)
- **CVSS Score:** N/A (Severity categorized as important per Canadian Centre for Cyber Security)
- **CWE:**
- CWE-287 (Improper Authentication - TOTP Replay)
- CWE-284 (Improper Access Control - Delegation binding)
- CWE-20 (Improper Input Validation - Model alias key)
## Affected Systems
- **Products:** MISP (Malware Information Sharing Platform)
- **Versions:** All versions prior to **2.5.48**
- **Configurations:** Systems utilizing Multi-Factor Authentication (TOTP) and Event Delegation features are at higher risk.
## Vulnerability Description
MISP version 2.5.48 addresses several security-relevant logic flaws:
1. **TOTP Reuse:** The system failed to invalidate TOTP codes after a successful login, potentially allowing for replay attacks.
2. **Improper Delegation Binding:** Authorized delegation requests were not strictly bound to their specific events, potentially leading to unauthorized access.
3. **Data Integrity/Persistence Flaw:** An issue where a nested model alias key incorrectly selected rows during save operations, and a flaw in tag collection saves that could lead to unintended writes to sibling user/org rows.
## Exploitation
- **Status:** Fixed; No reports of exploitation in the wild at time of advisory.
- **Complexity:** Medium
- **Attack Vector:** Network
## Impact
- **Confidentiality:** Moderate (Potential unauthorized access to event data)
- **Integrity:** Moderate (Unintended database writes/row selection during saves)
- **Availability:** Low
## Remediation
### Patches
- **Upgrade to MISP version 2.5.48** or later. The patches are integrated into the main branch.
### Workarounds
- No official workarounds provided; immediate patching is the recommended course of action.
## Detection
- **Indicators of Compromise:** Review audit logs for multiple successful logins using the same TOTP token in a short timeframe. Monitor for unexpected modifications to organizational or user rows following tag updates.
- **Detection methods:** Check version status via the MISP diagnostic tool within the web UI.
## References
- Vendor Security Page: hxxps[://]www[.]misp-project[.]org/security/
- TOTP Fix: hxxps[://]github[.]com/MISP/MISP/commit/a020fa47b
- Delegation Fix: hxxps[://]github[.]com/MISP/MISP/commit/d1f5684f9
- Model Alias Fix: hxxps[://]github[.]com/MISP/MISP/commit/9485ae40d
- Cyber Centre Advisory: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/misp-security-advisory-av26-986