5.2.4

Security

  • Fixed security bug that would allow read access to system files -SW
  • Fixed potential SQL injection in notification search -SW
  • Fixed possible XSS in startdate and enddate fields in reports -SW
  • Fixed XSS injection possibility in menu system -SW
  • Fixed XSS injection possibility in my reports -SW

Fixed

  • Fixed system API endpoint to allow POST requests for applyconfig and importconfig -JO
  • Fixed restore_xi.sh script to use manage_services.sh instead of service -JO
  • Fixed two+ line title dashlet buttons not being clickable [TPS#7247] -JO
  • Fixed bug causing gethistoricalservicestatus backend cmd to not have a valid time -SW
  • Fixed GUI based upgrade to use proxy configuration -SW
  • Fixed SLA report PDF from duplicating table headers across multiple pages, overlaying other table items [TPS#7297] -SW
  • Fixed issue in BPI component where ; was being used instead of :: for services [TPS#7367] -SS
  • Fixed current outdated retention.dat not being added to backups causing program state to not be retained correctly [TPS#7416] -SW
  • Fixed admin users able to have “Read-only user” permission -JO
  • Fixed searching for hosts and services where object name contained : [TPS#7463] -SW
  • Fixed restore_xi.sh to work for restoring oldersystem which use postgresql [TPS#7467] -SW
  • Fixed bug where searching in manage users to sometimes reverted to edit page of previous user [TPS#7471] -SW
  • Fixed install on CentOS 7.2+ systems that do not come with firewalld pre-installed -JO
  • Fixed Host Status Summary links not displaying correctly in dashlets [TPS#7616] -BH
  • Fixed FreeIPA LDAP server working with user importing [TPS#7552] -SS
  • Fixed Capacity Planning PDF report hanging system [TPS#7149] -BH
  • Fixed Custom URL Dashlet ignoring width/height [TPS#7448] -BH
  • Fixed Scheduled Downtime incorrectly picking some dates [TPS#7476] -BH
  • Fixed Warning/Critical Display setting not working in Capacity Planning report [TPS#7514] -BH
  • Fixed LDAP Import of UPPERCASE username causing report functionality to break [TPS#7555] -BH
  • Fixed non-highcharts perfgraph dashlet links [TPS#7633] -BH
  • Fixed scheduled report menu-item addition/removal [TPS#7679] -BH
  • Fixed SLA report ignoring advanced options [TPS#7685] -BH
  • Fixed bug in Availability report utilizing incorrect assumed service states for warning and unknown [TPS#7690] -LG
  • Fixed bug in Scheduled Downtime where the chosen date format was not being respected [TPS#7692] -LG
  • Fixed repair_databases.sh not checking for MySQL DB nagiosxi [TPS#7730] -BH
  • Fixed Hard coded base_url’s in scheduled reports allowing for different base_url’s -SW
  • Fixed Graph Explorer component’s multistacked graph from sometimes overwriting a selected item when adding items to graph -SS

Component Updates

Core Config Manager (CCM) 2.5.3

  • Fixed bug allowing filtering when adding host/service to contact notification commands [TPS#7207] -LG
  • Fixed bug where removing CCM users was not working properly [TPS#7540] -BH
  • Fixed import to properly check for duplicates [TPS#7551] -BH
  • Fixed Hard coded base_url -SW