FEDORA-2021-5f7da70bfe created by mikaku 3 months ago for Fedora 33
stable

Security fix for [CVE-2021-3325].

This new version fixes a security bug introduced in the 3.13.0 version that lead the HTTP built-in server to bypass the Basic Authentication when the option hosts_deny is not defined, which is the default.

Besides this fix, this version also updates the main configuration file to add the option hosts_deny = all by default inside the auth subsection, in an attempt to make the default behaviour more clear.

All users using the 3.13.0 version are advised and encouraged to upgrade to this new version, which resolves the security issue.


This new version introduces three new modules: the long-awaited pgsql.pm capable of monitoring up to 9 databases of an unlimited number of PostgreSQL servers, the redis.pm and tinyproxy.pm which are both also capable of monitoring an unlimited number of Redis and Tinyproxy servers respectively.

This version also includes some interesting new features. The new CSS theming support will allow people to create their own color themes. The new support for the ss command in port.pm and nginx.pm modules. The ability to map the device names and also to include a title name in disk.pm module. The new stacked visualization of network stats available on a number of modules, and more.

Also with this new version, Monitorix is able to be executed as a regular user instead of root. This is of course subject to the capabilities of each module to get statistics without using the superuser.

The rest of new features, changes and bugs fixed are, as always, reflected in the Changes file.

How to install

sudo dnf upgrade --advisory=FEDORA-2021-5f7da70bfe

This update has been submitted for testing by mikaku.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago

This update's test gating status has been changed to 'waiting'.

3 months ago

This update has obsoleted monitorix-3.13.0-2.fc33, and has inherited its bugs and notes.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago

This update has been pushed to testing.

3 months ago

mikaku edited this update.

3 months ago

mikaku edited this update.

3 months ago

This update can be pushed to stable now if the maintainer wishes

2 months ago

This update has been submitted for stable by bodhi.

2 months ago

This update has been pushed to stable.

2 months ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-1
Stable by Karma
1
Stable by Time
7 days
Dates
submitted
3 months ago
in testing
3 months ago
in stable
2 months ago
modified
3 months ago
BZ#1920998 monitorix-3.13.1 is available
0
0
BZ#1921333 CVE-2021-3325 monitorix: Basic Authentication bypass in a default installatio [fedora-all]
0
0

Automated Test Results