Security Releases – Horizon 29.0.3, Meridians 2021.1.8, 2020.1.16, 2019.1.27
Today we released updates to all OpenNMS Meridian versions under active support, as well as Horizon 29, to address the Log4j2 "Log4Shell" vulnerability.
Today we released updates to all OpenNMS Meridian versions under active support, as well as Horizon 29, to address the Log4j2 "Log4Shell" vulnerability.
Updates The log4j.formatMsgNoLookups work-around is no longer recommended. We are evaluating CVE-2021-45105 and at this time do not believe our products are affected. December 14, 2021: Horizon 26.1.2 and earlier versions. December 16, 2021: CVE-2021-45046. December 20, 2021: CVE-2021-45105. Note: Major text changes appear in red Background Serious remote code [...]
In December, we released updates to all OpenNMS Meridian versions under active support, as well as Horizon 29.
Since last time, we worked on config management and validation, OIA, VMware collection, Twin API tracing, documentation, Collectd, IPC, Enlinkd, Karaf, flow thresholding, Pollerd, router config backup, discovery `exclude-url`, BMP telemetry RRDs, JAAS and Setinel, FeatherDS UI updates, Vue geomaps, smoke tests, and Helm.
Since last time, we worked on docs, Karaf support and config migration in the config management API, the Twin API, Maven component mapping, integration test fixes, VMware support, flow thresholding, collector and Enlinkd improvements, OIA on the Minion, file editing in the new UI, the Vue geomap, requisition editing, and REST APIs.
Since last time, we worked on migrating configs to the database, documentation improvements, the Twin API, SNMP metadata, Maven, the Zabbix adapter, alarms in Sentinel, JAXB processing, Karaf, Collectd, Alarmd and ALEC collections, the Vue geomap, and the new FeatherDS UI.
Horizon 29.0.1 is a quick release outside of the normal schedule to address some bugs found in 29.0.0 mostly related to running as non-root, and Minion communication.
Since last time, we worked on Provisiond, Karaf, Enlinkd and LLDP, the config management API, documentation, Sentinel, the Twin API, running as non-root, Maven improvements, Pollerd, IPv6 in the GeoIP provisioning adapter, config validation, flows, Azure PostgreSQL support, Kafka, Geomaps, FeatherDS Vue UI, and Helm.
In November, we released updates to all OpenNMS Meridian versions under active support, and introduced a new major release of Horizon.
Since last time, we prepped for Horizon 29 and worked on Zabbix agent support, test fixes, Karaf, the Twin API, documentation, the config management API, SNMPv3 settings, macOS Monterey fixes, schema handling, gRPC, PostgreSQL, SQS, Minion, REST, JavaMail TLS, GeoIP provisioning, Enlinkd LLDP, healthcheck, the web config editor, vue Geomaps, and the new featherDS UI.