5.2.4
- February 18, 2016
Security
- Fixed security bug that would allow read access to system files -SW
- Fixed potential SQL injection in notification search -SW
- Fixed possible XSS in startdate and enddate fields in reports -SW
- Fixed XSS injection possibility in menu system -SW
- Fixed XSS injection possibility in my reports -SW
Fixed
- Fixed system API endpoint to allow POST requests for applyconfig and importconfig -JO
- Fixed restore_xi.sh script to use manage_services.sh instead of service -JO
- Fixed two+ line title dashlet buttons not being clickable [TPS#7247] -JO
- Fixed bug causing gethistoricalservicestatus backend cmd to not have a valid time -SW
- Fixed GUI based upgrade to use proxy configuration -SW
- Fixed SLA report PDF from duplicating table headers across multiple pages, overlaying other table items [TPS#7297] -SW
- Fixed issue in BPI component where ; was being used instead of :: for services [TPS#7367] -SS
- Fixed current outdated retention.dat not being added to backups causing program state to not be retained correctly [TPS#7416] -SW
- Fixed admin users able to have “Read-only user” permission -JO
- Fixed searching for hosts and services where object name contained : [TPS#7463] -SW
- Fixed restore_xi.sh to work for restoring oldersystem which use postgresql [TPS#7467] -SW
- Fixed bug where searching in manage users to sometimes reverted to edit page of previous user [TPS#7471] -SW
- Fixed install on CentOS 7.2+ systems that do not come with firewalld pre-installed -JO
- Fixed Host Status Summary links not displaying correctly in dashlets [TPS#7616] -BH
- Fixed FreeIPA LDAP server working with user importing [TPS#7552] -SS
- Fixed Capacity Planning PDF report hanging system [TPS#7149] -BH
- Fixed Custom URL Dashlet ignoring width/height [TPS#7448] -BH
- Fixed Scheduled Downtime incorrectly picking some dates [TPS#7476] -BH
- Fixed Warning/Critical Display setting not working in Capacity Planning report [TPS#7514] -BH
- Fixed LDAP Import of UPPERCASE username causing report functionality to break [TPS#7555] -BH
- Fixed non-highcharts perfgraph dashlet links [TPS#7633] -BH
- Fixed scheduled report menu-item addition/removal [TPS#7679] -BH
- Fixed SLA report ignoring advanced options [TPS#7685] -BH
- Fixed bug in Availability report utilizing incorrect assumed service states for warning and unknown [TPS#7690] -LG
- Fixed bug in Scheduled Downtime where the chosen date format was not being respected [TPS#7692] -LG
- Fixed repair_databases.sh not checking for MySQL DB nagiosxi [TPS#7730] -BH
- Fixed Hard coded base_url’s in scheduled reports allowing for different base_url’s -SW
- Fixed Graph Explorer component’s multistacked graph from sometimes overwriting a selected item when adding items to graph -SS
Component Updates
Core Config Manager (CCM) 2.5.3
- Fixed bug allowing filtering when adding host/service to contact notification commands [TPS#7207] -LG
- Fixed bug where removing CCM users was not working properly [TPS#7540] -BH
- Fixed import to properly check for duplicates [TPS#7551] -BH
- Fixed Hard coded base_url -SW
