Funnelback patch 16.2.0.5

  • Released: 2021-05-18

  • Applies to: v16.2.0

  • Internal reference: RNDSUPPORT-3374

Description

  • Fixes a cross-site scripting vulnerability in Freemarker templates.

Affected files

  • web/templates/modernui/funnelback.ftl

Deployment

  • Stop the Jetty web server.

  • (16.2.0.4) Stop the Daemon service.

  • Deploy the provided files on top of an existing install, backing up all replaced files.

  • (16.2.0.1) It is recommended that the following (empty) file is deleted: lib/java/all/commons-codec-1.9.jar.

  • (16.2.0.2) Update the first line of the bin/reports-send-email.pl script to refer to the correct perl interpreter for your Funnelback installation. The perl interpreter can be found in $SEARCH_HOME/conf/executables.cfg.

  • Start the Jetty web server.

  • (16.2.0.4) Start the Daemon service.