<div dir="ltr">In times like this, container tools (podman or docker) would be greatly appreciated.<br></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">Em seg., 3 de ago. de 2026 às 09:38, Barry O'Donovan (INEX) via ixpmanager <<a href="mailto:ixpmanager@inex.ie">ixpmanager@inex.ie</a>> escreveu:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg3892814794054542381">
<div style="color:rgb(0,0,0)"><div><div id="m_3892814794054542381x9140601ec6334375918773069135940a"><div><br></div>
<div>Hi all,</div><div><br></div><div>Both security issues below have been assigned CVE IDs CVE-2026-63339 and CVE-2026-63338, respectively.</div><div><br></div><div>The reporter who responsibly disclosed these issues plans to publish more details (including the PoC and the root cause) on the oss-security mailing list.</div><div><br></div><div>We have agreed that they will wait until August 11th, 2026, 12:00 UTC before publishing.</div><div><br></div><div>If you have not already upgraded your IXP Manager installation to v7.3.1, you should do so within the next week.</div><div><br></div><div> - Barry</div><div><br></div><div id="m_3892814794054542381signature_old"></div></div></div><div id="m_3892814794054542381signature_old">
<br>
</div><div><br></div>
<div><br></div>
<div>
<div>------ Original Message ------</div>
<div>From "Barry O'Donovan (INEX)" <<a href="mailto:barry.odonovan@inex.ie" target="_blank">barry.odonovan@inex.ie</a>></div>
<div>To "INEX IXP Manager Mailing List" <<a href="mailto:ixpmanager@inex.ie" target="_blank">ixpmanager@inex.ie</a>></div>
<div>Date 30/06/2026 19:33:47</div>
<div>Subject [RELEASE] V7.3.0 - Security Updates (severity: high) , App Passwords feature, API keys modernisation, bug fixes</div></div><div><br></div>
<div id="m_3892814794054542381x73827ea42e3c4e6" style="color:rgb(0,0,0)"><blockquote cite="http://em4c2fc216-a1b1-4281-a03d-e11e550e93e2@inex.ie" type="cite" class="m_3892814794054542381cite2">
<div><br></div><div><div id="m_3892814794054542381xb88fe02089f2495eae99d1ee657b1103"><div style="margin:0px"><br></div><div style="margin:0px">INEX is pleased to announce the immediate availability of IXP Manager v7.3.0. This is primarily a security release following a responsible disclosure and subsequent internal hardening. Both issues have a high severity. This release also includes some bug fixes, improvements, and new features.</div><div style="margin:0px"><br></div><div style="margin:0px">⚠️ All IXP Manager users should upgrade to v7.3.0.</div><div style="margin:0px"><br></div><div style="margin:0px"><br></div><div style="margin:0px"><br></div><div style="margin:0px"><u><b>Our Continuing Security Commitment & EU CRA Alignment</b><br></u><br>As IXP Manager powers critical internet infrastructure globally, security is core to our processes, and this is <i><b>the fourth successive release</b></i> primarily focused on security. We have also used third-party reporting as a catalyst to perform proactive internal audits of our codebase, leading to the discovery and immediate mitigation of additional vulnerabilities.<br><br>Also, with the European Union’s Cyber Resilience Act mandatory reporting requirements taking effect this September, INEX is cognisant of our legal role as an Open-Source Software Steward. To meet these obligations, we have reviewed and updated our <a href="https://github.com/inex/IXP-Manager/security/policy" target="_blank">Security Policy</a>. <br></div><div style="margin:0px"><br></div><div style="margin:0px"><br></div><div style="margin:0px"><b><u>Security Advisory: Vulnerabilities Resolved in v7.3.0</u></b></div><div style="margin:0px"><br></div><div style="margin:0px"><b>Impact:</b> High (Privilege Escalation & Unauthorised Access)<br><br><ol style="list-style-type:decimal"><li><span>Privilege Escalation (CVE pending</span><span>) (Severity: 8.8/10) - a</span><span> confirmed vulnerability allows an authenticated, non-administrative user to elevate their privileges to administrator status. This was responsibly disclosed</span><span>.</span></li><li><span>Broken Object-Level Authorisation (CVE pending) </span><span>(Severity: 8.3/10) - f</span><span>ollowing the initial report of (1) above, our development team conducted a proactive internal audit. During this review, we identified and corrected an issue in which an authenticated user could view and edit a resource belonging to another user without authorisation.</span></li></ol><b>Remediation:</b> Both issues are addressed in this v7.3.0 release. Please upgrade to v7.3.0 as soon as possible.<br></div><div style="margin:0px"><br></div><div><br></div>
<div style="margin:0px"><br></div><div id="m_3892814794054542381signature_old" style="clear:both;margin:0px"><br>
Kind regards,
<br>
Barry O'Donovan
<br>
INEX</div><div id="m_3892814794054542381signature_old" style="clear:both;margin:0px"></div></div></div><div><br></div>
<div><br></div><div id="m_3892814794054542381signature_old">
<br>
</div><div><br></div></blockquote></div>
</div>_______________________________________________<br>
INEX IXP Manager mailing list<br>
<a href="mailto:ixpmanager@inex.ie" target="_blank">ixpmanager@inex.ie</a><br>
Unsubscribe or change options here: <a href="https://www.inex.ie/mailman/listinfo/ixpmanager" rel="noreferrer" target="_blank">https://www.inex.ie/mailman/listinfo/ixpmanager</a><br>
</div></blockquote></div><div><br clear="all"></div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature"><div dir="ltr">Douglas Fernando Fischer<br>Engº de Controle e Automação<br><div style="padding:0px;margin-left:0px;margin-top:0px;overflow:hidden;color:black;text-align:left;line-height:130%;font-family:"courier new",monospace"></div></div></div>