2.1.9

Security

  • Fixed several XSS in Admin > Audit Log (thanks Liew Hock Lai and NCC Group) (CVE-2021-35478, CVE-2021-35479) -SAW
  • Fixed XSS in Configure > Config Snapshots (CVE-2020-25385) -SAW

Updated

  • Alert ownership no longer changes automatically when edited by an administrator [TPS#15264] -SAW
  • Changed default real-time alert creation behavior
  • when using “in” or “not in” operators, the create/update logic will assume a string on the left criterion and a field/property on the right unless specified -SAW

Fixed

  • Fixed issue with Python 2 compatibility -JO,DC