Welcome, Guest. Please login or register.

Author Topic: NeDi 1.9 Update  (Read 2317 times)

rickli

  • Administrator
  • Hero Member
  • *****
  • Posts: 2893
    • View Profile
    • NeDi
NeDi 1.9 Update
« on: February 09, 2021, 06:33:10 pm »
Security researcher Veno Eivazian found some vulnerabilities in Nodes-Traffic and Monitoring-History (only exploitable by authenticated users). I thank him for contacting me thus helping to improve NeDi! He mentioned System-Files as well, but as this module can perform actual software updates and is only accessible by admins, any "mitigation" would defeat its purpose.

Please update NeDi 1.9 with this patch https://www.nedi.ch/pub/nedi-1.9C1.ptc

I?ve also provided Patch4 for NeDi 2.0 in the customer area.

The good news is that NeDi 2.1 is on a good track for release by the end of March. It'll contain many usability and visual improvements as the new dashboard picture shows..
Please consider Other-Invoices on your NeDi installation for an annual contribution, tx!
-Remo

migas62

  • Newbie
  • *
  • Posts: 13
    • View Profile
Re: NeDi 1.9 Update
« Reply #1 on: February 12, 2021, 03:49:14 pm »
Hi,

IS it possible to exclude devices based on the hostname or device type?

tanx
Miguel

rickli

  • Administrator
  • Hero Member
  • *****
  • Posts: 2893
    • View Profile
    • NeDi
Re: NeDi 1.9 Update
« Reply #2 on: February 22, 2021, 11:31:59 am »
Yes, there's a namefilter regexp-option in nedi.conf
Please consider Other-Invoices on your NeDi installation for an annual contribution, tx!
-Remo