<html theme="default-light" iconset="color"><head>
<meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body
 style="font-family: Calibri; font-size: 14px;" text="#485663">
<div style="font-size: 14px;font-family: Calibri;">
INEX is pleased to announce the availability of IXP Manager 
v7.3.1. This is a security release following a responsible disclosure. 
The issue reported has been assigned severity critical.<br>

  <br>

⚠️ All IXP Manager users should upgrade to v7.3.1.<br>

  <br>

  <span style="font-weight: bold;">Security Policy & EU CRA 
Alignment</span><br>

  <br>

As IXP Manager powers critical internet infrastructure globally, 
security is core to our processes, and this is the fifth successive 
release primarily focused on security. We accept responsibly-disclosed 
security vulnerability reports and we have also used third-party 
reporting as a catalyst to perform proactive internal audits of our 
codebase, leading to the discovery and mitigation of 
additional vulnerabilities.<br>

  <br>

Also, with the European Union’s Cyber Resilience Act mandatory reporting
 requirements taking effect this September, INEX acknowledges its 
legal role as an Open-Source Software Steward. These obligations are 
reflected in our <a 
href="https://github.com/inex/IXP-Manager/security/policy">Security 
Policy</a>.<br>

  <br>

  <span style="font-weight: bold;">Security Advisory: Vulnerabilities 
Resolved in v7.3.1</span><br>

  <br>

  <span style="font-weight: bold;">Impact:</span> Critical (RCE via 
authenticated access)<br>

  
<ul><li>Remote Code Execution (CVE pending) (CVSS 3.1 Base Severity: 
9.9) - a confirmed vulnerability allows an authenticated, 
non-administrative user to execute code on the IXP Manager hosting 
environment.
 This was responsibly disclosed by 9Bakabaka.<br>
    </li></ul>

  <span style="font-weight: bold;">Remediation:</span> This issue is 
addressed in the v7.3.1 release. Please upgrade to v7.3.1 as soon as 
possible.<br>

  <br>

  <br>

Kind regards,<br><br>

Nick Hilliard<br>

INEX<br>

  <br>



</div>
</body>
</html>