We fixed two security vulnerabilities related to the web interface. They were related to the cross-site request forgery attack and the clickjacking attack. Both are used to induce users to perform actions that they do not intend to perform by hiding the NetEye web interface under some eye-catching pages or with some malicious links sent for example by email.
More information on how the vulnerabilities work can be found here:
Furthermore, we fixed a bug related to the users SSO in the ITOA module. When the users belonged to teams of different organizations, the teams were not correctly assigned.
For NetEye 4.17 we updated the following packages:
httpd-neteye-config and httpd-neteye-config-autosetup to version 1.9.1-1
icingaweb2-module-analytics and icingaweb2-module-analytics-autosetup to version 1.38.1-1
Mattia Codato
Software Developer - IT System & Service Management Solutions at Würth IT Italy
Author
Mattia Codato
Software Developer - IT System & Service Management Solutions at Würth IT Italy
Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.49 2.15.6_neteye1.73.1-1 Summary This release fixes authorization Read More
RKE2 Otel Collector DNS requirement During updates and first installations on systems where the Elastic Stack feature module was installed, an extra requirement was present. In particular, the DNS defined in the resolv.conf of the machine was required to resolve Read More
Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 9.4.5_neteye3.103.7-1 CVEs Elasticsearch Read More
GLPI 11 install and upgrade issue We identified and fixed a bug that could cause the neteye install or neteye upgrade command to fail on clusters in case the service was not running on the same node as Icingaweb2 Keycloak Read More
Resolved issue affecting neteye update We identified and fixed a bug that could cause the neteye update command to fail under specific circumstances. List of updated packages To solve the issue mentioned above, the following packages have been updated for Read More