[ixpmanager-announce] [RELEASE] V5.6.0 - Security Fix, Per-Member Document Store and Bug Fixes

Barry O'Donovan barry.odonovan at inex.ie
Sat May 23 11:23:23 IST 2020


We are pleased to announce the immediate availability of IXP Manager 
v5.6.0.

This release primarily adds a new Per-Member Document Store feature to 
IXP Manager **and fixes a security issue**. It also has a small number 
of bug fixes and improvements. All IX's running < v5.6.0 are advised to 
upgrade.


**Security Fix**

This release includes a fix for a security bug introduced in v4.9.0.

The bug allows a logged in non-administrator user to affect changes to a 
non-service affecting database table.

To allow people a chance to upgrade, we will delay publishing more 
information on the security issue until Friday, May 29th 2020. If any 
IXP cannot upgrade in that time frame, please email any of myself, Nick 
or Yann from an official IXP email address and we will provide a quick fix.

Credit to David Croft (@davidc), an elected member director of LONAP, 
for finding and responsibly disclosing this issue.

Full details at:

https://github.com/inex/IXP-Manager/releases/tag/v5.6.0

  - Barry

-- 

Kind regards,
Barry O'Donovan
INEX



More information about the ixpmanager-announce mailing list