[Release] Checkmk stable release 2.3.0p8

Dear friends of Checkmk,

the new stable release 2.3.0p8 of Checkmk is ready for download.

This stable release ships with 17 changes affecting all editions of Checkmk,
7 changes for the Enterprise editions, 0 Cloud Edition specific and
0 Managed Services Edition specific changes.

Changes in all Checkmk Editions:

Checks & agents

  • 16845 SEC: fix a privilege escalation vulnerability in the Checkmk Windows Agent…
  • 17112 FIX: ICMP Echo Request (Ping): Off-by-one error in active check…
    NOTE: Please refer to the migration notes!
  • 17070 FIX: Agent controller on Linux: More informative error message in case of file reading errors in import mode…
  • 17110 FIX: Don’t crash on broken plugins unless in debug mode…
  • 17111 FIX: JVM garbage collectors: Collection time off by factor of 100
  • 17109 FIX: More helpful error handling for broken plugins…
  • 16435 FIX: agent_netapp_ontap: Fix TypeError for SnapVault…
  • 16862 FIX: snmp: Fix error in SNMP context serialization…

Setup

  • 17090 SEC: Fix Various CSRF Issues…
  • 17075 FIX: Fix regex error when using global flags when matching multiple expressions…

User interface

  • 17059 SEC: Escape user input on load failure of visuals…
  • 17001 FIX: Enable several host actions no matter the tree depth of existing hosts…
  • 16743 FIX: Fix vertical graph range if it does not start at zero
  • 17071 FIX: Graphs with legend in dashboards: Avoid crash if dashlet is too short to contain graph…
  • 17000 FIX: Preserve search term after deletion of topics, bookmarks or custom sidebar elements…
  • 16999 FIX: Service check commands exclamation mark is no more escaped…
  • 17057 FIX: Use correct filter for virtual host tree links…

Changes in the Checkmk Enterprise Edition:

Agent Bakery

  • 16716 SEC: Mitigate timing-unsafe comparisons to prevent byte-by-byte brute forcing attack…
  • 16434 SEC: Synthetic Monitoring: Privilege Escalation…

Checks & agents

  • 16433 FIX: Synthetic Monitoring: Report RCC Profile Configuration Errors…

Core & setup

  • 16513 Add option to change the maximum response size for livestatus…

Notifications

  • 16661 Notification Spooler: Support IPv6…

REST API

  • 16717 FIX: Fix DCD creation using the Rest API…

User interface

  • 17080 FIX: Hanging background jobs/frozen site…

Changes in the Checkmk Cloud Edition:

NO CHANGES

Changes in the Checkmk Saas Edition:

NO CHANGES

Changes in the Checkmk Managed Services Edition:

NO CHANGES

You can download Checkmk from our download page: Download Checkmk for free | Checkmk

List of all changes: Werks

We greatly thank you for using Checkmk and wish you a successful monitoring,

Your Checkmk Team

Due to Werk 17090 some buttons do not work anymore. We are currently working on the fixes for that and are planning a release with these fixes shortly.


Is there currently another way to activate the master switch here? This also results in the “No CSRF token received” message

We already fixed the problem. You can use 2.3.0p9

1 Like