We fixed two security vulnerabilities related to the web interface. They were related to the cross-site request forgery attack and the clickjacking attack. Both are used to induce users to perform actions that they do not intend to perform by hiding the NetEye web interface under some eye-catching pages or with some malicious links sent for example by email.
More information on how the vulnerabilities work can be found here:
Furthermore, we fixed a bug related to the users SSO in the ITOA module. When the users belonged to teams of different organizations, the teams were not correctly assigned.
For NetEye 4.17 we updated the following packages:
httpd-neteye-config and httpd-neteye-config-autosetup to version 1.9.1-1
icingaweb2-module-analytics and icingaweb2-module-analytics-autosetup to version 1.38.1-1
Mattia Codato
Software Developer - IT System & Service Management Solutions at Würth IT Italy
Author
Mattia Codato
Software Developer - IT System & Service Management Solutions at Würth IT Italy
NATS: Fix multi-tenancy configuration corruption in cluster environments When executing commands such as neteye install --restrict-services-to nats-server, neteye tenant config apply, or neteye satellite config create from a cluster node while nats-server was active on a different node, the shared Read More
Important: Grafana security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the grafana packages is now available for NetEye 4. Security Fix for NetEye 4.49 and 4.50 grafana-12.4.12_neteye3.31.4-1 Summary Four medium-severity CVEs Read More
Fixes for nginx and nginx-satellite We identified and fixed two issues affecting nginx resource management during service and resource restarts. nginx-satellite.service An issue could leave nginx worker processes running after nginx-satellite.service entered a failed state. These processes could continue listening Read More
When the GLPI inventory plugin is used to collect agent inventories, assets may fail to appear in GLPI even though the agents reach the server. The cause was a bug in the Icinga Web 2 SSO plugin: GLPI 11 marks Read More
Keycloak: Fix for Oversized Logout URL and Package Update This update addresses an issue where the logout redirect URL became excessively large, leading to failed logouts and HTTP 500 errors. When users belonged to a large number of groups, the Read More