An update for the package lampod is now available for NetEye 4.
NetEye Product Security has rated this update as having a security impact of Important. Common Vulnerability Scoring System (CVSS) base scores provide additional guidance about a vulnerability and give a detailed severity rating.
Description
lampod is a NetEye package used for searching across the most important entities such as hosts, configurations etc.
An improper input validation causes Cross Site Scripting when the element is displayed in lampo navigation (CWE-79)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the links listed in the References section.
Solution
Update lampod to latest version (1.1.2-1).
For details on how to apply this update, which includes the changes described in this advisory, refer to the NetEye Update Section inside the User Guide.
Affected Products
All NetEye 4.x versions prior to and including 4.30
We have resolved an issue that could have led to the failure of the installation process during initial setups. This problem arose from a temporary absence of an entry in the /etc/hosts file, which in turn hindered the startup of Read More
We have implemented a verification step in the neteye install, update, and upgrade processes to verify Kibana's connectivity to the fleet integration endpoint when the NetEye instance operates behind a proxy without direct Internet access. Additionally, we have revised our Read More
We updated the Elastic Stack to version 8.15.2, which fixes some known issues present with versions 8.15.1 (the version previously used in NetEye for Elasticsearch, Kibana, Logstash and APM) and 8.15.0 (the version previously used in NetEye by Elastic Agents Read More
We fixed a bug in nginx that was causing NetEye upgrades from version 4.36 to version 4.37 to fail with an error. We updated the following packages: nginx-neteye-config, nginx-neteye-config-autosetup, nginx-neteye-config-configurator to version 1.14.2-1
Core Neteye install, update, upgrade procedures individual service logs weren't saved in the correct format We resolved a small issue where logs from parallel install or configurator playbooks were wrongly manipulated resulting in a different format from what they were Read More