An update for the package icingaweb2-module-director is now available for NetEye 4.
NetEye Product Security has rated this update as having a security impact of High. Common Vulnerability Scoring System (CVSS) base scores provide additional guidance about a vulnerability, and give a detailed severity rating.
Description
Icinga Director is a tool for the configuration of Icinga 2 distributed with NetEye 4.
It enables attackers to perform changes in the monitoring environment managed by Icinga Director without the awareness of a potential victim.
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the links listed below in the References section.
Solution
Update the icingaweb2-module-director package to 1.11.1_neteye1.36.2-1.
For details on how to apply this update, which includes the changes described in this advisory, refer to the NetEye Update Section in the User Guide.
Affected Products
All NetEye 4.x versions before and including 4.34.
We have resolved an issue that could have led to the failure of the installation process during initial setups. This problem arose from a temporary absence of an entry in the /etc/hosts file, which in turn hindered the startup of Read More
We have implemented a verification step in the neteye install, update, and upgrade processes to verify Kibana's connectivity to the fleet integration endpoint when the NetEye instance operates behind a proxy without direct Internet access. Additionally, we have revised our Read More
We updated the Elastic Stack to version 8.15.2, which fixes some known issues present with versions 8.15.1 (the version previously used in NetEye for Elasticsearch, Kibana, Logstash and APM) and 8.15.0 (the version previously used in NetEye by Elastic Agents Read More
We fixed a bug in nginx that was causing NetEye upgrades from version 4.36 to version 4.37 to fail with an error. We updated the following packages: nginx-neteye-config, nginx-neteye-config-autosetup, nginx-neteye-config-configurator to version 1.14.2-1
Core Neteye install, update, upgrade procedures individual service logs weren't saved in the correct format We resolved a small issue where logs from parallel install or configurator playbooks were wrongly manipulated resulting in a different format from what they were Read More