Centreon Web 24.10.15
Enhancements
- [API Tokens] Added a welcome page when no token exists in the token configuration page.
- [Authentication] Password change attempts are now logged in a dedicated log file.
- [Authentication] When editing a contact, users authenticated by an IdP no longer see the password editing fields.
- [Configuration] The “Deploy Service” action from the hosts list now triggers a “Conf Changed” flag for the related poller in the pollers list.
- [Configuration] Fixed an issue with database partitioning on Amazon Aurora RDS. The next update may take a bit longer for some users while the system catches up.
- [Resource Status] For performance and readability reasons, graphs containing more than 20 metrics are no longer displayed.
- [UI] Changed wording from “IP Address” to “Address” for pollers.
Bug fixes
- [ACL] Fixed an issue for users cumulating multiple ACLs that caused the ACL with the highest ID to override other ones.
- [API] Fixed an issue where using Rest APIv1 would change the token expiration date.
- [API] Fixed an issue that caused commands to return an SQL error when requesting services in real time using MySQL 8.
- [API] Fixed an issue with filtering on realtime service categories listing API endpoint.
- [APIv2] Fixed a 500 error when using expiration_date = NULL in security_token.
- [Anomaly Detection] Fixed an issue on broker configuration generation with proxy parameters.
- [Authentication] Allowed to access Centreon UI through a reverse proxy/load balancer.
- [Authentication] Fixed an issue on LDAP authentication.
- [Authentication] Fixed an issue where users could lose their DN during an LDAP connection.
- [Authentication tokens] Fixed an issue when clicking “cancel” in the change confirmation modal that caused the token’s status to be displayed as changed.
- [CLAPI] Fixed an issue where HTML entities were not correctly decoded when exporting.
- [CLAPI] Fixed an issue where the APPLYTPL command woul take a long time to take effect.
- [Configuration] Fixed an error when changing the host template order in the host configuration form.
- [Configuration] Fixed an issue in Agent configuration where engine was not listening if “No TLS” was activated (poller-initiated).
- [Configuration] Fixed an issue on Agent configuration where results of filters were not as expected if there was no matching data.
- [Configuration] Fixed an issue where host names could be saved with special characters but would then cause “export configuration” to fail.
- [Configuration] Fixed an issue on remote servers, where max auto_increment was reached after many exports causing imports to fail.
- [Configuration] Fixed an issue preventing users from disabling a meta-service.
- [Configuration] Fixed an issue in Agent configuration (Poller-initiated connection) that prevented users from searching for the host.
- [Configuration] Fixed an issue where configuration files were not generated when the poller was disabled in the listing and re-enabled through the form.
- [configuration] Fixed an issue where configuration wasn’t exported for hosts without alias and declared in agent configuration.
- [Configuration] Fixed an issue where inputs/outputs were missing when duplicating a Broker config.
- [Configuration] Fixed an issue where Host categories were not displayed in the listing when not linked to Host.
- [Core] Fixed an issue where the log level wasn’t being taken into account in the token removal script.
- [Custom Views - Host-Monitoring] Fixed an issue where only the current page was exported instead of all data.
- [Dashboards] Fixed an issue preventing to get dashboards filtered.
- [Dashboards] Fixed an issue where host status icons were displayed incorrectly in the group monitoring widget.
- [Dashboards] Single Metric widget - Fixed the real-time retrieval of metric values.
- [Downtimes] Fixed an issue with meta-service names not being properly displayed.
- [Host groups] Fixed an issue while checking for illegal characters on host group name.
- [Licences] Fixed an error message concerning the creation of a dynamic property in a class when downloading licences.
- [LDAP Import] Fixed an issue where a LDAP user with a UID containing a special character would be imported multiple times.
- [Log] Fixed an issue where “Error impCompanyPortal” would appear on /var/log/centreon/centreon-web.log.
- [Monitoring] Fixed an issue on Host Group Summary redirecting users to Resource Status.
- [Packaging] Updated permissions of token purge log file
- [Performance Graphs] Fixed an issue when exporting data in CSV that resulted in an empty file.
- [Resource Status] Fixed error when displaying metrics of a meta service.
- [Resource Status] Services related to a deleted host will no longer appear in menu filter.
- [Translation] Fixed an issue where menu language was set to FR when the “Detection by browser” language option was selected.
- [Translations] Fixed an issue preventing translations from being displayed.
Security fixes
- [Security] Enhanced security on password DOM storage in login page.
- [Security] Fixed an RCE vulnerability on poller reload page.
- [Security] Secured backup script to prevent command injections.
- [Vulnerability] Fixed an issue on Broken Access Control in Administration Parameters Endpoint.
- [Vulnerability] Fixed IDOR vulnerability on Custom Views.
- [Vulnerability] Fixed XSS vulnerability in Configuration > Hosts > hostgroups.
- [Vulnerability] Fixed vulnerability XSS in the ACL Menus Access page.
- [Vulnerability] Fixed XSS vulnerability in the Hosts Configuration page.
- [Vulnerability] Fixed XSS vulnerability in the Recurrent Downtimes page.

