Update 2019-03-28-MISP.2.4.105.released.md

iglocska-patch-1
Andras Iklody 2019-03-28 17:58:00 +01:00 committed by GitHub
parent d8b34d5a66
commit ecd7a0348f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 3 additions and 3 deletions

View File

@ -4,11 +4,11 @@ layout: post
featured: /assets/images/misp/blog/distribution-graph.png
---
A new version of MISP ([2.4.105](https://github.com/MISP/MISP/tree/v2.4.105)) has been released to fix a security vulnerability CVE-2019-10254, minor improvements and a fix for STIX 1.1 files to be imported with additional namespaces (such as [CISCP](https://www.dhs.gov/cisa/cyber-information-sharing-and-collaboration-program-ciscp)).
A new version of MISP ([2.4.105](https://github.com/MISP/MISP/tree/v2.4.105)) has been released to fix a security vulnerability (CVE-2019-10254) in addition to some minor improvements and a fix for the STIX 1.1 import, enabling the import of fileswith additional namespaces (such as [CISCP](https://www.dhs.gov/cisa/cyber-information-sharing-and-collaboration-program-ciscp)).
This release includes a security fix to a reflected XSS (CVE-2019-10254) in the default layout template as reported by Tuscany Internet eXchange | Misp Team | TIX CyberSecurity (Thanks to them!). We strongly recommend everyone to update to this version.
This release includes a security fix for a reflected XSS (CVE-2019-10254) vulnerability in the default layout template as reported by Tuscany Internet eXchange | Misp Team | TIX CyberSecurity (Thanks to them!). We strongly recommend that everyone update their MISPs to the latest version.
STIX import in 1.1 can now import STIX files with any additional namespaces (such as [CISCP](https://www.dhs.gov/cisa/cyber-information-sharing-and-collaboration-program-ciscp)).
The STIX 1.1 import can now import STIX files using additional, non-standard namespaces (such as [CISCP](https://www.dhs.gov/cisa/cyber-information-sharing-and-collaboration-program-ciscp)).
# Improvements