<html theme="default-light" iconset="color"><head>
<meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body
style="font-family: Calibri; font-size: 14px;" text="#485663">
<div style="font-size: 14px;font-family: Calibri;">
INEX is pleased to announce the availability of IXP Manager
v7.3.1. This is a security release following a responsible disclosure.
The issue reported has been assigned severity critical.<br>
<br>
⚠️ All IXP Manager users should upgrade to v7.3.1.<br>
<br>
<span style="font-weight: bold;">Security Policy & EU CRA
Alignment</span><br>
<br>
As IXP Manager powers critical internet infrastructure globally,
security is core to our processes, and this is the fifth successive
release primarily focused on security. We accept responsibly-disclosed
security vulnerability reports and we have also used third-party
reporting as a catalyst to perform proactive internal audits of our
codebase, leading to the discovery and mitigation of
additional vulnerabilities.<br>
<br>
Also, with the European Union’s Cyber Resilience Act mandatory reporting
requirements taking effect this September, INEX acknowledges its
legal role as an Open-Source Software Steward. These obligations are
reflected in our <a
href="https://github.com/inex/IXP-Manager/security/policy">Security
Policy</a>.<br>
<br>
<span style="font-weight: bold;">Security Advisory: Vulnerabilities
Resolved in v7.3.1</span><br>
<br>
<span style="font-weight: bold;">Impact:</span> Critical (RCE via
authenticated access)<br>
<ul><li>Remote Code Execution (CVE pending) (CVSS 3.1 Base Severity:
9.9) - a confirmed vulnerability allows an authenticated,
non-administrative user to execute code on the IXP Manager hosting
environment.
This was responsibly disclosed by 9Bakabaka.<br>
</li></ul>
<span style="font-weight: bold;">Remediation:</span> This issue is
addressed in the v7.3.1 release. Please upgrade to v7.3.1 as soon as
possible.<br>
<br>
<br>
Kind regards,<br><br>
Nick Hilliard<br>
INEX<br>
<br>
</div>
</body>
</html>