Executive brief
The MISP threat intelligence platform's Azure Active Directory (AAD) login plugin contained several security flaws in how it handled user sessions and authentication requests. These weaknesses could allow an attacker to hijack a user's session, trick users into logging into an attacker-controlled account, or intercept sensitive login credentials if the connection is not properly secured. This could lead to unauthorized access to sensitive threat data and administrative functions within the platform.
Technical details
The MISP AadAuth plugin suffered from multiple OAuth 2.0 implementation flaws. Specifically, it used the PHP session_id() as the OAuth 'state' parameter, leaking session tokens via Referer headers and logs. It failed to regenerate session IDs after login (CWE-384), enabling session fixation. The 'state' parameter was not a single-use nonce, weakening CSRF and replay protections. Additionally, the plugin did not enforce HTTPS for redirect URIs, potentially exposing authorization codes in plaintext, and lacked sanitization for OAuth error logging, allowing for log injection. A fix has been implemented in the MISP repository to introduce cryptographically random state values, session rotation, and HTTPS enforcement.
Affected products
- MISP MISP <= 2.5.41
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory