Common Gateway Security Fixes
Enhanced Security for Linux Kernel
The OpsRamp Gateway includes a security fix for the Linux kernel vulnerability identified. The update ensures that Ethernet MAC headers are properly validated before access, helping prevent potential system instability or unauthorized access during network traffic processing. Upgrade to the latest Gateway version to apply the security fix and maintain a more secure and resilient Gateway environment.
Enhanced Security for Linux-Based Deployments
Resolved a security issue in affected Linux environments that could allow an unauthorized local user to gain elevated system privileges under specific conditions. Security updates and kernel-level protections have been implemented to mitigate the risk, strengthen access controls, and enhance the overall security of Linux-based deployments.
NextGen Gateway Security Fixes
Enhanced Security for NextGen Gateway
OpsRamp has updated the NextGen Gateway (Ubuntu 22 appliance) to address multiple critical and high-severity vulnerabilities. By upgrading to the latest version or applying the provided manual patches, you can ensure your gateway environment is protected against identified risks in core packages such as openssl, openssh, curl, bind9, and the Linux kernel. This update strengthens your overall security posture and ensures compliance with recommended safety standards.
Enhanced Security for Browser
OpsRamp has updated the NextGen Gateway to include the latest security patches for Chromium-based components, addressing multiple vulnerabilities including a critical zero-day flaw. This update protects your environment against potential exploits that could allow unauthorized code execution through malicious web content. By maintaining the most current browser engine versions, you ensure a more secure and resilient gateway infrastructure.
We recommend the following workaround depending on your Gateway type.
- If you are upgrading to version 21.2.3, no action is required. The patch will automatically update the chrome package.
- If you are not upgrading to version 21.2.3, you can still manually update the affected packages by following the instructions provided in the documentation below:
- For NextGen Gateway, see Update Instructions page.
- For Classic Gateway, see Update Instructions page.