Most of the 11 CVEs are authorization and access control weaknesses affecting Kibana, including Missing/Incorrect Authorization (Fleet metadata disclosure, ML resource abuse, Entity Store API key creation, APM credential disclosure, AI Assistant Knowledge Base tampering, unauthorized ML data reads, disabled Entity Analytics monitoring) and resource-exhaustion issues in Agent Builder and Streams content packs, within the Elastic Stack. The remaining CVE is an Incorrect Permission Assignment for Critical Resource in Elastic Agent, affecting unprivileged Windows installations, that can lead to local privilege escalation to SYSTEM. Together, these CVEs can lead to unauthorized information disclosure, privilege escalation, data tampering, or denial of service.
When the GLPI inventory plugin is used to collect agent inventories, assets may fail to appear in GLPI even though the agents reach the server. The cause was a bug in the Icinga Web 2 SSO plugin: GLPI 11 marks Read More
Keycloak: Fix for Oversized Logout URL and Package Update This update addresses an issue where the logout redirect URL became excessively large, leading to failed logouts and HTTP 500 errors. When users belonged to a large number of groups, the Read More
Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the glpi packages is now available for NetEye 4. Security Fix for NetEye 4.49 glpi-11.0.9_neteye1.20.3-2 glpi-autosetup-11.0.9_neteye1.20.3-2 glpi-configurator-11.0.9_neteye1.20.3-2 Summary This is the Read More
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49: 26.7.4_neteye1.46.1-1 Summary This Keycloak update (version Read More