NetEye Product Security has rated this update as having a high security impact.
Topic
An update for the grafana packages is now available for NetEye 4.
Security Fix for NetEye 4.49
grafana-12.4.11_neteye3.31.3-1
Summary
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana’s configured datasource credentials to users who lack permission to query that datasource.
For details on how to apply this update, which includes the changes described in this advisory, refer to the NetEye Update Section in the User Guide.
Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.50 9.5.5_neteye3.105.3-1 CVEs Elastic Read More
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.50: 26.8.0_neteye1.47.1-1 Summary This Keycloak update (version Read More
OIDC group synchronization with read-only LDAP federation Fixed an issue that occurred when OIDC group synchronization was enabled alongside a read-only LDAP federation. The OIDC mapper attempted to modify LDAP-managed group memberships, resulting in the error: Not possible to delete Read More
Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the glpi packages is now available for NetEye 4. Security Fix for NetEye 4.50 glpi-11.0.11_neteye1.25.3-1 glpi-autosetup-11.0.11_neteye1.25.3-1 glpi-configurator-11.0.11_neteye1.25.3-1 glpi-neteye-config-11.0.11_neteye1.25.3-1 Summary This is Read More
NATS: Fix multi-tenancy configuration corruption in cluster environments When executing commands such as neteye install --restrict-services-to nats-server, neteye tenant config apply, or neteye satellite config create from a cluster node while nats-server was active on a different node, the shared Read More