5.8.3

Security

  • Updated email validation to require RFC 822 valid email addresses to fix possible security vulnerabilities -JO
  • Fixed XSS vulnerability in user Email Address field when on Send Test Notification page -JO
  • Fixed possible RCE vulnerability via Email Address not being properly validated (CVE-2020-24899) -JO

Updated

  • Updated jQuery to version 3.6.0 to fix minor issues -JO

Fixed

  • Fixed install process on Oracle Linux 8 due to mod_php being used instead of php-fpm like CentOS/RHEL -JO
  • Fixed config/ endpoints to properly display array of contacts (and other objects) when using append (+) in config [TPS#15509] -JO
  • Fixed argument quoting in mysqlrepair and restore_xi scripts -DC,JO
  • Fixed issue with Scheduled Backups sending local backup success email with SSH or FTP emails [TPS#15501] -JO
  • Fixed API help/example PUT config calls not working properly due to space not being url encoded [TPS#15505] -JO
  • Fixed scheduled reports jobs not changing with username change [TPS#15502] -JO
  • Fixed issue where masquerade button in the Manage Users page wasn’t working on some OS/PHP versions -JO
  • Fixed issues with MIB integration after upgrading to SNMPTT 1.4.2 [TPS#15376] -SAW
  • Fixed issues with Undo Trap Processing button [TPS#15500] -SAW
  • Fixed issue with downgraded ndo2db systems where limited users would not properly load data due to is_ndo_loaded failing -JO