This update for icingaweb2 to version 2.7.3 fixes the following issues:
icingaweb2 update to 2.7.3:
icingaweb2 update to 2.7.2:
icingaweb2 update to 2.7.1:
icingaweb2 update to 2.7.0:
icingaweb2 update to 2.6.3:
icingaweb2 update to 2.6.2:
You can find issues and features related to this release on our Roadmap. This bugfix release addresses the following topics:
Fix security issues:
CVE-2018-18246: fixed an CSRF in moduledisable (boo#1119784)
CVE-2018-18247: fixed an XSS via /icingaweb2/navigation/add (boo#1119785)
CVE-2018-18248: fixed an XSS attack is possible via query strings or a dir parameter (boo#1119801)
CVE-2018-18249: fixed an injection of PHP ini-file directives involves environment variables as channel to send out information (boo#1119799)
CVE-2018-18250: fixed parameters that can break navigation dashlets (boo#1119800)
Remove setuid from new upstream spec file for following dirs:
/etc/icingaweb2, /etc/icingaweb/modules, /etc/icingaweb2/modules/setup, /etc/icingaweb2/modules/translation, /var/log/icingaweb2
icingaweb2 updated to 2.6.1:
icingaweb2 was updated to 2.6.0:
You can find issues and features related to this release on our Roadmap.
{
"binaries": [
{
"icingacli": "2.7.3-bp151.5.3.1",
"icingaweb2": "2.7.3-bp151.5.3.1",
"icingaweb2-common": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-HTMLPurifier": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-JShrink": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-Parsedown": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-dompdf": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-lessphp": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-zf1": "2.7.3-bp151.5.3.1",
"php-Icinga": "2.7.3-bp151.5.3.1"
}
]
}
{
"binaries": [
{
"icingacli": "2.7.3-bp151.5.3.1",
"icingaweb2": "2.7.3-bp151.5.3.1",
"icingaweb2-common": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-HTMLPurifier": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-JShrink": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-Parsedown": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-dompdf": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-lessphp": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-zf1": "2.7.3-bp151.5.3.1",
"php-Icinga": "2.7.3-bp151.5.3.1"
}
]
}
{
"binaries": [
{
"icingacli": "2.7.3-bp151.5.3.1",
"icingaweb2": "2.7.3-bp151.5.3.1",
"icingaweb2-common": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-HTMLPurifier": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-JShrink": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-Parsedown": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-dompdf": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-lessphp": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-zf1": "2.7.3-bp151.5.3.1",
"php-Icinga": "2.7.3-bp151.5.3.1"
}
]
}
{
"binaries": [
{
"icingacli": "2.7.3-bp151.5.3.1",
"icingaweb2": "2.7.3-bp151.5.3.1",
"icingaweb2-common": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-HTMLPurifier": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-JShrink": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-Parsedown": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-dompdf": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-lessphp": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-zf1": "2.7.3-bp151.5.3.1",
"php-Icinga": "2.7.3-bp151.5.3.1"
}
]
}
{
"binaries": [
{
"icingacli": "2.7.3-bp151.5.3.1",
"icingaweb2": "2.7.3-bp151.5.3.1",
"icingaweb2-common": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-HTMLPurifier": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-JShrink": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-Parsedown": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-dompdf": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-lessphp": "2.7.3-bp151.5.3.1",
"icingaweb2-vendor-zf1": "2.7.3-bp151.5.3.1",
"php-Icinga": "2.7.3-bp151.5.3.1"
}
]
}