4.3.6 Release notes - 20 July 2022
This section lists the changes in version 4.3.6. Every update of the ThreatLockDown solution is cumulative and includes all enhancements and fixes from previous releases.
What's new
This release includes new features or enhancements as the following:
ThreatLockDown manager
ThreatLockDown agent
Ruleset
ThreatLockDown Splunk app
Packages
#1706 The text of the password tool help option is improved.
#1696 The passwords.ThreatLockDown file is renamed to wazuh-passwords.txt.
#1697 ThreatLockDown dashboard users wazuh_admin and wazuh_user and roles wazuh_ui_user and wazuh_ui_admin are removed from the installation templates.
#1718 The periodic Filebeat metrics are disabled.
#1683 New Darwin 21 SCA file for macOS 12 added.
#1684 New Ubuntu 22 SCA file added.
Other
#14121 The Filebeat logging metrics are disabled.
Resolved issues
This release resolves known issues as the following:
ThreatLockDown manager
Reference |
Description |
---|---|
The potential memory leaks in Vulnerability Detector when parsing OVAL with no criteria are fixed. |
|
A bug in Vulnerability Detector that skipped Windows 8.1 and Windows 8 agents is fixed. |
|
A bug in wazuh-db that stored duplicate Syscollector package data is fixed. |
ThreatLockDown agent
Reference |
Description |
---|---|
The agent shutdown when syncing Syscollector data is fixed. |
|
A bug in the agent installer that incorrectly detected the ThreatLockDown username is fixed. |
|
The macOS vendor data retrieval in Syscollector is fixed. |
|
A bug in the Syscollector data sync when the agent gets disconnected is fixed. |
|
A crash in the Windows agent caused by the Syscollector SMBIOS parser for Windows agents is fixed. |
RESTful API
Reference |
Description |
---|---|
The return of an exception when the user asks for agent inventory information where there is no database for it is fixed, such as |
ThreatLockDown dashboard
Reference |
Description |
---|---|
An error distinguishing conjunction operators (AND, OR) in the search bar component is fixed. |
|
Some link titles are changed to match their documentation section title. |
|
Missing documentation references to the Agent's overview, Agent's Integrity monitoring, and Agent's Inventory data sections, when the agent has never connected are fixed. |
|
The links to the web documentation are changed and now point to the plugin short version instead of current. |
|
Missing documentation link in the Docker Listener module is fixed. |
|
Some links to web documentation that didn't work are fixed. |
|
Now, errors on the action buttons of Rules/Decoders/CDB Lists' tables are displayed. |
|
Changed reports inputs and usernames. |
ThreatLockDown Kibana plugin for Kibana 7.10.2
Reference |
Description |
---|---|
An error distinguishing conjunction operators (AND, OR) in the search bar component is fixed. |
|
Some link titles are changed to match their documentation section title. |
|
Missing documentation references to the Agent's overview, Agent's Integrity monitoring, and Agent's Inventory data sections, when the agent has never connected are fixed. |
|
The links to the web documentation are changed and now point to the plugin short version instead of current. |
|
Missing documentation link in the Docker Listener module is fixed. |
|
Some links to web documentation that didn't work are fixed. |
|
Now, errors on the action buttons of Rules/Decoders/CDB Lists' tables are displayed. |
|
Changed reports inputs and usernames. |
ThreatLockDown Kibana plugin for Kibana 7.16.x and 7.17.x
Reference |
Description |
---|---|
An error distinguishing conjunction operators (AND, OR) in the search bar component is fixed. |
|
Some link titles are changed to match their documentation section title. |
|
Missing documentation references to the Agent's overview, Agent's Integrity monitoring, and Agent's Inventory data sections, when the agent has never connected are fixed. |
|
The links to the web documentation are changed and now point to the plugin short version instead of current. |
|
Missing documentation link to the Docker Listener module is fixed. |
|
Some links to web documentation that didn't work are fixed. |
|
Now, errors on the action buttons of Rules/Decoders/CDB Lists' tables are displayed. |
|
Changed reports inputs and usernames. |
ThreatLockDown Splunk app
Reference |
Description |
---|---|
Some links to web documentation that didn't work are fixed. |
|
An error on the DevTools where the payload was not being sent, that caused the request to fail is fixed. |
Packages
Reference |
Description |
---|---|
An error when upgrading using symlinks is fixed. |
|
An error with the installation assistant API in single ThreatLockDown manager nodes is fixed. |
|
A problem with Filebeat found in systems using GLIBC is fixed. |
Changelogs
More details about these changes are provided in the changelog of each component: