Blog Entries

20. 08. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4.49 – Security Advisory (Icinga 2)

Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.49 Summary This release fixes authorization bypasses in /v1/events filter expressions and a node-to-node memory-exhaustion DoS, while also preventing sensitive data from…

Read More
17. 08. 2026 Davide Sbetti Bug Fixes, NetEye

Bug Fixes for NetEye 4.49

RKE2 Otel Collector DNS requirement During updates and first installations on systems where the Elastic Stack feature module was installed, an extra requirement was present. In particular, the DNS defined in the resolv.conf of the machine was required to resolve the domain set as frontend domain the in the /etc/neteye-environment.yaml. This requirement was now dropped…

Read More
14. 08. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 CVEs Elasticsearch Fleet Server Kibana Most of the 36 CVEs are Denial of Service vulnerabilities affecting Elasticsearch (uncontrolled…

Read More
12. 08. 2026 Davide Sbetti Bug Fixes, NetEye

Bug Fixes for NetEye 4.49

GLPI 11 install and upgrade issue We identified and fixed a bug that could cause the neteye install or neteye upgrade command to fail on clusters in case the service was not running on the same node as Icingaweb2 Keycloak install issue We identified and fixed a bug that could cause the neteye install command…

Read More
29. 07. 2026 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.47

Resolved issue affecting neteye update We identified and fixed a bug that could cause the neteye update command to fail under specific circumstances. List of updated packages To solve the issue mentioned above, the following packages have been updated for NetEye 4.47:

Read More
28. 07. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4.46 – Security Advisory (Icinga 2)

Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.46 Summary The vulnerabilities include an authentication bypass leading to privilege escalation via trusted CA impersonation, a stack-based buffer overflow, and an…

Read More
28. 07. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4.47 – Security Advisory (Icinga 2)

Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.47 Summary The vulnerabilities include an authentication bypass leading to privilege escalation via trusted CA impersonation, a stack-based buffer overflow, and an…

Read More
28. 07. 2026 Cecilia Marchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (NagVis)

Important: NagVis security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the nagvis and icingaweb2-module-nagvis packages is now available for NetEye 4. Security Fix for NetEye 4.48 Summary The vulnerabilities include two livestatus injections in dynmaps and a XSS via WYSIWYG editor. For details on how to…

Read More
24. 07. 2026 Gabriele Bocchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a Medium security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.48 CVEs Elasticsearch Kibana Most of the 15 CVEs are Denial of Service vulnerabilities affecting Elasticsearch (ES|QL, EQL, search-query parsing) and Kibana…

Read More
23. 07. 2026 Davide Zeni Bug Fixes, NetEye

Bug Fixes for NetEye 4.48

Fix Soft States Some checks that were actually failing showed up as green/OK in Icinga. The cause: two parts of the system stored the same status in different formats, so the web interface misread it and hid early-stage problems. A fix aligns the formats, List of updated packages To solve the issue mentioned above, the…

Read More
16. 07. 2026 Davide Zeni Bug Fixes, NetEye

Bug Fixes for NetEye 4.48

Fix Director self-service api We fixed the uncaught exception on bad Basic autm but in doing so we introduced a 302 redirect for API requests as well. Net result: a curl client expecting a 401 gets redirected to the login page instead, and the machine on the other end has no browser to follow it….

Read More
07. 07. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4.48 – Security Advisory (Icinga 2)

Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.48 Summary The vulnerabilities include an authentication bypass leading to privilege escalation via trusted CA impersonation, a stack-based buffer overflow, and an…

Read More
07. 07. 2026 Gabriele Bocchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a Medium security impact. Topic An update for the Kibana package is now available for NetEye 4. Security Fix for NetEye 4.48 CVEs All of the 3 CVEs are Denial of Service vulnerabilities that affect Kibana, within the Elastic Stack. Affected Products All…

Read More
01. 07. 2026 Gabriele Bocchi Bug Fixes, NetEye

Bug Fixes for NetEye 4.48

Fix Geo Map layers and maps deletion. We have resolved an issue in the Geo Map module that prevented users from deleting maps and layers through the web interface. List of updated packages To solve the issue mentioned above, the following packages have been updated for NetEye 4.48:

Read More
24. 06. 2026 Gabriele Bocchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (GLPI)

Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the glpi packages is now available for NetEye 4. Security Fix for NetEye 4.48 Summary The vulnerabilities include two SQL injections, an Arbitrary file deletion, a Privilege Escalation via authtype API manipulation, an Unauthorized debug mode…

Read More

Archive