OPNsense Forum

Administrative => Announcements => Topic started by: AdSchellevis on April 18, 2016, 01:50:35 pm

Title: OPNsense 16.1.11 released
Post by: AdSchellevis on April 18, 2016, 01:50:35 pm
Hi everyone,

We are skipping a bit ahead with 16.1.11 to address a CSRF vulnerability, which shows us the good path we have been on since we started[1] and we will surely continue this security-aware trend.

In other news, this update includes native GeoIP alias support, captive portal voucher customisations requested by many and the last batch of Russian, effectively bringing it to 100% completed. Wow!

Here is the full change log:

o services: fix CSRF vulnerability in status_services.php[2]
o www: strengthen CSRF secret generation for legacy pages
o dhcp: bring back usage of the authoritative directive
o system: allow periodic backups of RRD and DHCP for non-MFS
o captive portal: add option for less secure passwords, password and username length
o firewall: add GeoIP aliases feature
o openvpn: status page would not show the correct process status
o languages: completed Russian translation (contributed by Smart-Soft Ltd.)
o languages: updated French

Stay safe,
Your OPNsense team

[1] https://forum.opnsense.org/index.php?topic=2837.0 (https://forum.opnsense.org/index.php?topic=2837.0)
[2] https://cxsecurity.com/issue/WLB-2016040106 (https://cxsecurity.com/issue/WLB-2016040106)