09-01-2022 04:17 AM
Hi,
can anyone from Extreme tell me, when you plan to release a new feature version of XIQ OnPrem?
This is getting ridiculous, no big feature update for one and half year, we still have to use 21.1.x, so January 2021 version according to your scheme.
Solved! Go to Solution.
10-21-2022 06:13 AM
Hello,
Allow me to simplify. As the bulletin says, "In certain configurations, an attacker could execute arbitrary commands with the privileges of the script." In IQVA, yes, c_rehash is present. However, IQVA does not use it in any process, the configurations required for exploit are non-existent, and access to the OS in any capacity to expose it is not exposed. Several other CVE's are being tackled in the January release, specifically CVE-2021-4034. And no, the January release is not a joke, and is currently tracking as follows:
02-23-2023 07:02 AM
@daniel1 I just spoke to the team that's doing it and you should see it in the next week or so. QA testing is complete, the final build approved, and release notes should be finalized today (2/23). Then we just have to work to get it posed.
09-12-2022 06:51 AM
It's unfortunate to hear that Extreme presents their OnPrem customers a "Go to Cloud or die" choice.
04-17-2023 05:18 AM
The update is available now
Download: hivemanager-ng-upgrade-pack-21.1.23.4-IQVA-2023-02-16.tar.signed | Extreme Portal (force.c...
09-01-2022 04:50 AM - edited 09-14-2022 08:36 AM
While IQVA has been announced EOS, we are planning on a release of IQVA in the Dec/January timeframe. It will feature several bug fixes, updated features, support for DTLS 1.2, and new AP support for the new "-1" SKU's (no bluetooth).
10-20-2022 05:47 AM - edited 10-20-2022 05:47 AM
Hi @BillL ,
are you guys serious with this? Security Advisory: SA-2022-010 – OpenSSL (CVE-2022-1292) | Extreme Portal (force.com)
"IQVA – Will not be fixed. Please upgrade to XIQ."
I'm guessing that your "Dec/Jan release" was just a joke?