Released: November 2019

What's new?

  • WebTitan Active Directory Agent (WADA) discovered IP-to-user mappings are now viewable via the UI.

What has been improved?

  • The traffic database is no longer exported as part of the backup.

  • The default block page has been updated.

  • Disabled support for SSLv3 and disabled weak ciphers.

  • Removed support account from UI.

  • All patches and hotfixes are now fetched over HTTPS.

  • Removed obsolete YouTube for schools.

  • Login security upgraded with improved password hashing.

What has been fixed?

  • Handling of group names containing a comma.

  • A potential vulnerability in the backup/restore process that could allow the injection of malicious files onto the filesystem.

  • Formatting issues in PDF reports.

  • A potential vulnerability that may allow an unauthenticated user to access the database via the proxy service.

  • Report generation via the UI is canceled when the reporting database is on a separate appliance.

  • A policy manager is logged out when saving a policy.

  • The retention period was not reducing automatically even though disk space is approaching capacity.

  • Issue performing URL keyword filtering.

  • An XSS vulnerability in the cache manager.

  • A potential SQL injection vulnerability on the History and Reporting pages.

  • Access allowed to a database configuration file through the UI.

  • The categorization engine could incorrectly report a URL as unclassified.

  • Communication issue with the categorization engine causing it to hang.

  • Resolved a potential session fixation vulnerability.

  • Issue selecting the correct policy for users with a large number of groups (greater than 128).

  • WPAD autoconfiguration wizard misconfigures the BYPASS for networks setting.

  • Slow database reporting queries locking up the UI.

  • The saving of an invalid allowed domain appears as successful.

  • An authenticated administrator allowed to view log files which they are not authorized to view.