

Fixed an issue with logrotate permissions for the CentOS 9 OVA – DA.Fixed an issue that caused sound settings to not display correctly in the operation center – SG.Fixed SQL injection vulnerability in the accouncement banner configuration interface (Thanks Astrid Tedenbrant and Outpost24 for reporting this) (CVE-2023-40933) – BB.Fixed SQL injection vulnerability acknowledging an announcement banner (Thanks Astrid Tedenbrant and Outpost24 for reporting this) (CVE-2023-40931) – SG.Fixed XSS in Custom Logo component (Thanks Astrid Tedenbrant and Outpost24 for reporting this) (CVE-2023-40932) – AC.

Added security setting to block remote sites from loading via xiwindow parameter – DA.Added “Maximum Downtime History Age” to performance settings – SAW.Added the ability to resize some dashlets – SNS.Added fuzzy search to the Configuration Wizard page – SNS.
