2024R1.3.1

Security

  • Fixed a security vulnerability in history content tab (Thanks to Ruben Meeuwissen for reporting this) [GL:XI#1338] – DA
  • Fixed Neptune Tools allowing protocols other than HTTP and HTTPS (Thanks to Ruben Meeuwissen for reporting this) [GL:XI#1325] – DA
  • Fixed user enumeration vulnerability in deprecated backend API (Thanks to Ruben Meeuwissen for reporting this) [GL:XI#1326] – DA
  • Added host header verification option in security settings [GL:XI#1334] – DA

Removed

  • Removed the ability for read only users to add their own tools (Thanks to Ruben Meeuwissen for reporting this) [GL:XI#1324] – DA
  • Removed exclusion of net-snmp package on RHEL/Oracle 8 systems [GL:XI#1066] – SG
  • Removed superfluous links from Capacity Planning graphs – CN

Added

  • Added CSRF protection to favorites component (Thanks to Ruben Meeuwissen for reporting this) [GL:XI#1339] – DA
  • Added the ability to set TDS version in MSSQL Wizards and plugin. [XI:#1288] – CN,SG
  • Added NCPA 3 support in Ansible roles for the Deploy Agent feature. [GL:XI!1106] – MPB

Fixed

  • Cleaned up upgrade scripts [GL:XI!1121] – DA,BB
  • Cleaned up many PHP warnings displayed in logs across the application [GL:XI#1345] – JS
  • Fixed an issue where custom includes were not applied correctly in Neptune themes [GL:XI#1313] – SG
  • Fixed an issue where updating contacts created by template in the CCM could sometimes fail [GL:XI#1333] – JS
  • Fixed some checkboxes and UI interactions throughout the Neptune theme [GL:XI!1134] – DA
  • Fixed upgrade scripts in the case where the installtype variable isn’t determined. [GL#1352] – JM
  • Updated checking of xi-itype file during upgrades [GL:XI!1132] – DA
  • Updated Neptune Network Error Handling [GL:XI!1111] – DA
  • Updated styling for dialogs and fixed a variety of small errors with the Neptune theme [GL:XI!1128] – DA