Blog Entries

03. 10. 2026 Luca Tecchio Bug Fixes, NetEye

NetEye 4 – Security Advisory (GLPI)

Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the glpi packages is now available for NetEye 4. Security Fix for NetEye 4.50 Summary This is the list of vulnerabilities patched in this update: For details on how to apply this update, which includes the…

Read More
02. 10. 2026 Luca Tecchio Bug Fixes, NetEye

Bug Fixes for NetEye 4.50

NATS: Fix multi-tenancy configuration corruption in cluster environments When executing commands such as neteye install –restrict-services-to nats-server, neteye tenant config apply, or neteye satellite config create from a cluster node while nats-server was active on a different node, the shared /neteye/shared/nats-server/conf/multi-tenancy.conf configuration file could get corrupted. Unreplaced template placeholders (such as @@ACCOUNTS@@, @@TORNADO_IMPORTS@@, and @@TELEGRAF_IMPORTS@@)…

Read More
01. 10. 2026 Damiano Chini Bug Fixes, NetEye

NetEye 4 – Security Advisory (Grafana)

Important: Grafana security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the grafana packages is now available for NetEye 4. Security Fix for NetEye 4.49 and 4.50 Summary Four medium-severity CVEs were fixed (CVSS 4.3–5.4). Three concern permission scoping: alert rules listable from folders a user may…

Read More
30. 09. 2026 Davide Zeni Bug Fixes, NetEye

Bug Fixes for NetEye 4.49

Fixes for nginx and nginx-satellite We identified and fixed two issues affecting nginx resource management during service and resource restarts. nginx-satellite.service An issue could leave nginx worker processes running after nginx-satellite.service entered a failed state. These processes could continue listening on the configured ports and cause Address already in use errors during a restart. The…

Read More
24. 09. 2026 Patrick Harasser Bug Fixes, Log-SIEM, NetEye

Bug Fix for NetEye 4.49: Blocked GLPI Agent Inventories

When the GLPI inventory plugin is used to collect agent inventories, assets may fail to appear in GLPI even though the agents reach the server. The cause was a bug in the Icinga Web 2 SSO plugin: GLPI 11 marks the inventory plugin’s endpoints as “stateless,” and the SSO plugin wrongly treated them like static…

Read More
22. 09. 2026 Luca Tecchio Bug Fixes, NetEye

Bug Fixes for NetEye 4.49

Keycloak: Fix for Oversized Logout URL and Package Update This update addresses an issue where the logout redirect URL became excessively large, leading to failed logouts and HTTP 500 errors. When users belonged to a large number of groups, the ID token grew substantially (exceeding 8 KB) because the full group list was mapped into…

Read More
21. 09. 2026 Cecilia Marchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (GLPI)

Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the glpi packages is now available for NetEye 4. Security Fix for NetEye 4.49 Summary This is the list of vulnerabilities patched in this update: For details on how to apply this update, which includes the…

Read More
21. 09. 2026 Luca Tecchio Bug Fixes, NetEye

NetEye 4 – Security Advisory (Keycloak)

Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49: Summary This Keycloak update (version 26.7.4) resolves several security issues identified in upstream Keycloak: For details on how to apply this…

Read More
18. 09. 2026 Patrick Harasser Bug Fixes, NetEye

Bug Fixes for NetEye 4.49

Update of Elastic Stack to Version 9.4.7 Elastic Stack 9.4.7 delivers targeted fixes across Elasticsearch, Kibana, Fleet Server, Logstash, Elastic Observability, and Elastic Security. Elasticsearch improves memory protection, ES|QL correctness, kNN filtering, vector compatibility, and data-stream auto-sharding. Kibana addresses issues across dashboards, alerting, Fleet, and platform stability, while Fleet Server fixes version-specific agent re-enrollment, upgrade…

Read More
17. 09. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4 – Security Advisory (Grafana)

Important: Grafana security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the grafana packages is now available for NetEye 4. Security Fix for NetEye 4.49 Summary An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule…

Read More
15. 09. 2026 Luigi Miazzo Bug Fixes, NetEye

Bug Fixes for NetEye 4.47 and 4.48

NetEye upgrade causes RPMS of next release to be upgraded even if an update is required first We fixed a bug in NetEye 4.47 and 4.48 that caused the neteye upgrade command to update some NetEye packages even when packages from the previous version had not yet been installed by neteye update. List of updated…

Read More
09. 09. 2026 Davide Zeni Bug Fixes, NetEye

NetEye 4 – Security Advisory (Keycloak)

Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 Summary This Keycloak update (version 26.7.3) fixes 20 security issues found during internal review. None of them are rated Critical for running…

Read More
08. 09. 2026 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.46, 4.47, 4.48 and 4.49

Icinga 2 live-creation requests are no longer lost during reload During a Director deployment, Icinga 2 reloads its configuration in the background. Previously, live-creation requests could still be processed for a short time after a reload had been requested. This created a race condition: a request could be processed by the old Icinga 2 process…

Read More
03. 09. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 CVEs Elastic Agent Kibana Most of the 11 CVEs are authorization and access control weaknesses affecting Kibana, including…

Read More
26. 08. 2026 Davide Zeni Bug Fixes, NetEye

NetEye 4 – Security Advisory (Keycloak)

Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 Summary This vulnerability, tracked as CVE-2026-18963 (CVSS 9.1, Critical), affects the reset-credentials authentication flow in Keycloak. Due to improper state validation, an…

Read More

Archive