mirror of https://github.com/MISP/misp-website
				
				
				
			fix: [blog] MISP 2.4.121 release typo
							parent
							
								
									22a5999aaf
								
							
						
					
					
						commit
						4d9e223d41
					
				| 
						 | 
				
			
			@ -13,7 +13,7 @@ A new version of MISP ([2.4.121](https://github.com/MISP/MISP/tree/v2.4.121)) ha
 | 
			
		|||
The new version includes fixes to a set of vulnerabilities, kindly reported by Dawid Czarnecki. For details, see the attached CVE information.
 | 
			
		||||
 | 
			
		||||
- A reflected XSS in the galaxy view [CVE-2020-8893](https://cve.circl.lu/cve/CVE-2020-8893)
 | 
			
		||||
- ACL wasn't always correctly adhered to for the discussion threads [CVE-2020-8894](https://cve.circl.lu/cve/CVE-2020-8892)
 | 
			
		||||
- ACL wasn't always correctly adhered to for the discussion threads [CVE-2020-8894](https://cve.circl.lu/cve/CVE-2020-8894)
 | 
			
		||||
- Potential time skew between web server and database would cause the brute force protection not to fire.[CVE-2020-8890](https://cve.circl.lu/cve/CVE-2020-8890)
 | 
			
		||||
 | 
			
		||||
Whilst investigating the above, we have identified and resolved other issues with the brute force protection:
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
		Reference in New Issue