Most of the 8 CVEs are resource-exhaustion weaknesses in Elasticsearch. These are Uncontrolled Recursion, Uncontrolled Resource Consumption, Memory Allocation with Excessive Size Value, and Inefficient Regular Expression Complexity, found in scripted geometry runtime fields, the Connector API, and the ES|QL query engine and its CHUNK function. They let a low-privileged authenticated user crash a node or degrade it. Elasticsearch is also affected by an Authorization Bypass Through User-Controlled Key in cross-cluster search with the RCS 2.0 model, which can expose the contents of unauthorized indices. The remaining CVEs are an Incorrect Authorization in Kibana, which lets users with limited Fleet privileges get the SSL private keys of Fleet Server hosts, and an Uncaught Exception in Elastic Endpoint, which can repeatedly crash Elastic Defend on Windows hosts with CJK locales. Together, these CVEs can lead to unauthorized information disclosure, credential exposure, or denial of service.
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.50: 26.8.0_neteye1.47.1-1 Summary This Keycloak update (version Read More
OIDC group synchronization with read-only LDAP federation Fixed an issue that occurred when OIDC group synchronization was enabled alongside a read-only LDAP federation. The OIDC mapper attempted to modify LDAP-managed group memberships, resulting in the error: Not possible to delete Read More
Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the glpi packages is now available for NetEye 4. Security Fix for NetEye 4.50 glpi-11.0.11_neteye1.25.3-1 glpi-autosetup-11.0.11_neteye1.25.3-1 glpi-configurator-11.0.11_neteye1.25.3-1 glpi-neteye-config-11.0.11_neteye1.25.3-1 Summary This is Read More
NATS: Fix multi-tenancy configuration corruption in cluster environments When executing commands such as neteye install --restrict-services-to nats-server, neteye tenant config apply, or neteye satellite config create from a cluster node while nats-server was active on a different node, the shared Read More
Important: Grafana security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the grafana packages is now available for NetEye 4. Security Fix for NetEye 4.49 and 4.50 grafana-12.4.12_neteye3.31.4-1 Summary Four medium-severity CVEs Read More