Icinga Web 2 Version 2.8.3
What's New in Version 2.8.3
Notice: This is a security release. It is recommended to upgrade to this release if you don't plan to upgrade to v2.9.0.
You can find all fixes related to this release on our Project.
Security Fixes
This release includes two security related fixes. Both were published as part of a security advisory on Github.
They allow the circumvention of custom variable protection rules and blacklists as well as a path traversal if
the doc
module is enabled. Please check the respective advisory for details.
- Custom variable protection and blacklists can be circumvented GHSA-2xv9-886q-p7xx
- Possible path traversal by use of the
doc
module GHSA-cmgc-h4cx-3v43