<html theme="default-light" iconset="color"><head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
</head><body style="font-family: Calibri; font-size: 14px; color: 
rgb(72, 86, 99);" text="#485663"><div style="font-size: 
14px;font-family: Calibri;">
INEX is pleased to announce the availability of IXP Manager 
v7.3.1. This is a security release following a responsible disclosure. 
The issue reported has been assigned severity critical.<br>
  <br>
⚠️ All IXP Manager users should upgrade to v7.3.1.<br>
  <br>
  <span style="font-weight: bold;">Security Policy & EU CRA 
Alignment</span><br>
  <br>
As IXP Manager powers critical internet infrastructure globally, 
security is core to our processes, and this is the fifth successive 
release primarily focused on security. We accept responsibly-disclosed 
security vulnerability reports and we have also used third-party 
reporting as a catalyst to perform proactive internal audits of our 
codebase, leading to the discovery and mitigation of 
additional vulnerabilities.<br>
  <br>
Also, with the European Union’s Cyber Resilience Act mandatory reporting
 requirements taking effect this September, INEX acknowledges its 
legal role as an Open-Source Software Steward. These obligations are 
reflected in our <a 
href="https://github.com/inex/IXP-Manager/security/policy">Security 
Policy</a>.<br>
  <br>
  <span style="font-weight: bold;">Security Advisory: Vulnerabilities 
Resolved in v7.3.1</span><br>
  <br>
  <span style="font-weight: bold;">Impact:</span> Critical (RCE via 
authenticated access)<br>
  <ul>
    <li>Remote Code Execution (CVE pending) (CVSS 3.1 Base Severity: 
9.9) - a confirmed vulnerability allows an authenticated, 
non-administrative user to execute code on the IXP Manager hosting 
environment.
 This was responsibly disclosed by 9Bakabaka.<br>
    </li>
  </ul>
  <span style="font-weight: bold;">Remediation:</span> This issue is 
addressed in the v7.3.1 release. Please upgrade to v7.3.1 as soon as 
possible.<br>
  <br>
  <br>
Kind regards,<br><br>
Nick Hilliard<br>
INEX<br>
  <br>


</div></body></html>