|
After upgrading to 2.5.34.2, I get the error message described in the title, whenever I search for an event that has, for example, A way to avoid the exception is to use I have the same issue if I use What's the right way of handling misp events that have clusters/galaxies after this update? Thanks! |
Replies: 2 comments 1 reply
|
This is PyMISP pythonify, not MISP refusing the event. In 2.5.34,
Until PyMISP pops those fields on inbound default clusters instead of raising: def _strip_default_cluster_distribution(d):
if not isinstance(d, dict):
return d
# walk Event -> Galaxy -> GalaxyCluster (shape varies)
...or catch The check belongs on create/update of a cluster you own, not on parsing a default cluster the server already stored. A fix in |
|
That's a bug, I'll package a new release later today or tomorrow. |
This is PyMISP pythonify, not MISP refusing the event. In 2.5.34,
MISPGalaxyCluster.from_dict()errors whendefaultis true anddistributionis present. Default galaxy clusters (MITRE tags and the rest) are not something you attach a distribution to. The REST payload still includesdistributionon those objects, sopythonify=Trueblows up on search / add / update aftertag().pythonify=Falseworks because you never buildMISPGalaxyCluster.Until PyMISP pops those fields on inbound default clusters instead of raising:
or catch
NewGa…