Skip to content

Releases: OpenCTI-Platform/opencti

Version 7.260309.0-lts.3

10 Apr 14:33
e2f0ba5

Choose a tag to compare

Critical & security fixes:

  • #15158 User visibility outside non-org segregation does not work
  • #15267 Add an option to allow ElastisSearch 'filter' if really needed
  • #15272 OIDC configuration failing on Nonce mismatch since 7.260326.0

Direct security updates:

  • graphiql updated from 4.1.2 to 5.2.2
  • @apollo/server updated from 5.4.0 to 5.5.0
  • node-forge updated from 1.3.3 to 1.4.0
  • nodemailer updated from 8.0.1 to 8.0.4

Indirect security updates:

  • brace-expansion updated from 1.1.12 to 1.1.13
  • brace-expansion updated from 2.0.2 to 2.0.3
  • brace-expansion updated from 5.0.4 to 5.0.5
  • lodash updated from 4.17.23 to 4.18.1
  • picomatch updated from 2.3.1 to 2.3.2
  • picomatch updated from 4.0.3 to 4.0.4
  • yaml updated from 2.8.2 to 2.8.3
  • yaml updated from 1.10.2 to 1.10.3

Full Changelog: 7.260309.0-lts.2...7.260309.0-lts.3

Version 7.260409.0

09 Apr 15:08
a62019e

Choose a tag to compare

Enhancements:

  • #15347 Improve streams loading
  • #15201 Fix filters for related data
  • #15132 STIX 2.0 converter: Entities
  • #14727 Reorganize Entity Type customization page with horizontal tabs
  • #14649 [Connector Catalog] Name of Connector Not Captured
  • #13488 [Security coverage] Improvement of displayed results
  • #12023 The ability to set the polling frequency on a TAXII feed
  • #5376 Add the relationship type "belongs to" between Infrastructure and Organization

Bug Fixes:

  • #14254 In the data tab, ctrl+click on files is not working
  • #14269 Issue opening a PIR when queues are not set up properly
  • #14757 Dashboard: breakdown on horizontal/vertical bars
  • #14794 Connector scopes layout issue
  • #15171 Upgrade graphql-ws version
  • #15187 [BUG] batch_size not enforced as a cap in BatchCallbackWrapper
  • #15216 [Form Intake] "Disable on-the-fly entity creation" toggle rejected by backend schema validation
  • #15311 SSO: When using force env with local.config.disabled = true, local is not disabled
  • #15329 [RBAC] Capability descriptions not updated on existing instances after upgrade
  • #15339 Prevent re-rendering Settings right menu
  • #15360 [DOC] Fix typo issue on troubleshooting for SSO
  • #15371 When local strategy is disabled and user try to login with local "successully logged" is misleading
  • #15374 [BUG] convert_markdown() corrupts literal <code> text in entity descriptions during STIX bundle ingestion
  • #15418 Add templating tests

Pull Requests:

New Contributors:

Full Changelog: 7.260401.0...7.260409.0

Version 6.9.29

07 Apr 19:06
d8da0c0

Choose a tag to compare

Bug Fixes:

  • #15216 [Form Intake] "Disable on-the-fly entity creation" toggle rejected by backend schema validation
  • #14269 Issue opening a PIR when queues are not set up properly
  • #15267 Add an option to allow filter if really needed
  • #15218 Remove internal filter from API
  • #15158 User visibility outside non-org segregation does not work

Pull Requests:

Full Changelog: 6.9.28...6.9.29

Version 7.260401.0

01 Apr 13:33
ce80dd5

Choose a tag to compare

Enhancements:

  • #15131 STIX 2.0 converter: Techniques

Bug Fixes:

  • #15272 OIDC configuration failing on Nonce mismatch since 7.260326.0
  • #15226 Fix typos in the Spanish translations
  • #15213 Organization admin bad caps
  • #15084 Playbook "Manipulate Knowledge" does not serialize boolean value on initial component creation when switch is left at default (false)
  • #15013 [Diamond Model] Entity logos are not centered in the diamond corners
  • #14846 Overview of group, alignement issue
  • #14768 Activity: no more raw details anymore
  • #14676 [backend] Backend inconsistency between "vulnerability" and "vulnerabilities" in openAEV and openCTI STIX bundles
  • #14070 Unable to Edit Incident Content in Editor View
  • #11550 In settings, the right menu is re-rendering when swithing and should not

Pull Requests:

Full Changelog: 7.260326.0...7.260401.0

Version 7.260326.0

26 Mar 20:15
f4930dd

Choose a tag to compare

Enhancements:

  • #15109 [frontend] Integrate chatbot v2 React component
  • #15076 [DOC] execution traces of playbooks
  • #15057 Improve rescan operation by creating async version to prevent timeout errors
  • #14999 [RSSFeeds x XTMHub] - Ability to import/export RSS Feeds
  • #14338 Add new relationships to support vulnerability impact analysis
  • #14056 Worfklow: Ability in Draft to manage org sharing
  • #14015 Fix use of header for full synchronization
  • #13479 Add react flow to the platform
  • #11763 Playbook: Improve retention time display of execution logs

Bug Fixes:

  • #15158 User visibility outside non-org segregation does not work
  • #15151 2FA reset does not show trash anymore
  • #15090 Platform login message is not displayed in SSO only
  • #15078 Original creation date filter not available in Cases
  • #15039 [Bug] Connector trigger filters hardcoded to ['entity_type'] — regression from UI design system refactor
  • #15034 OIDC provider don't relay state
  • #15010 SSO V7 conversion of OpenID configuration without group mapping set a wrong default group configuration.
  • #15007 [BUG] Small memory leak in sseMiddleware sendEvent
  • #14996 SSO V7 GROUPS_MANAGEMENT__GROUPS_MAPPING empty fails on map is not a function
  • #14978 [Sighting] x_opencti_negative field is not updated on upsert

Pull Requests:

Full Changelog: 7.260318.0...7.260326.0

Version 7.260309.0-lts.2

23 Mar 16:25
5c07f57

Choose a tag to compare

Critical & security fixes

  • #14878 Handle release of LTS version
  • #14877 Live Stream Sync: File operations create infinite event loop in bidirectional sync
  • #14966 Error when clicking enrichment button after adding an external reference
  • #15017 [worker] Regression: opencti_operation set to 'event' instead of actual operation type in push_handler.py
  • #15027 Improve SSE resolutions
  • #14895 consumer drawer visible for every user
  • #14015 Fix use of header for full synchronization
  • #14169 Reducing allowed content in CSP
  • #14808 Login button label is not working in SAML configuration
  • #15026 SSO mappings expression should not be case sensitive
  • #15010 SSO V7 conversion of OpenID configuration without group mapping set a wrong default group configuration.
  • #14996 SSO V7 GROUPS_MANAGEMENT__GROUPS_MAPPING empty fails on map is not a function
  • #15034 OIDC provider don't relay state
  • #14920 Send retry in RabbitMQ improvements
  • #11790 Incorrect redirect after logout when using base_path
  • #15007 [BUG] Small memory leak in sseMiddleware sendEvent

Security updates

  • pyjwt updated from 2.11.0 to 2.12.0
  • dompurify updated from 3.3.1 to 3.3.3
  • express-rate-limit updated from 8.2.1 to 8.3.1
  • file-type updated from 21.3.0 to 21.3.3
  • tar updated from 7.5.9 to to 7.5.11
  • undici
    • opencti-front: updated from 7.22.0 to 7.24.4
    • opencti-graphql: updated from 6.23.0 to 6.24.1

Pull Requests:

Full Changelog: 7.260309.0-lts1...7.260309.0-lts.2

Version 7.260318.0

18 Mar 18:07
054dc0b

Choose a tag to compare

Enhancements:

  • #13593 [chatbot] Increase character limit for AI assistant questions
  • #14928 Pre-configured Copilot agents to easily get technical documentation

Bug Fixes:

  • #15014 [Bug] Indicator pattern display reverted to plain text in v7, code/indented view missing for SIGMA/YARA patterns
  • #15017 [worker] Regression: opencti_operation set to 'event' instead of actual operation type in push_handler.py
  • #14799 Connector detail view UI bug on hovering the "danger zone" in menu
  • #15026 SSO mappings expression should not be case sensitive
  • #15036 When trying to add a “has” relationship in the vulnerabilities menu, this is not always possible

Pull Requests:

New Contributors

Full Changelog: 7.260317.0...7.260318.0

Version 6.9.28

18 Mar 18:56
05fa3c6

Choose a tag to compare

No changelog for this release.

Pull Requests:

Full Changelog: 6.9.27...6.9.28

Version 7.260317.0

17 Mar 19:19
b758d0c

Choose a tag to compare

Enhancements:

  • #14288 Filter on 'description' attribute in Live streams, Notifiers, and Playbooks

Bug Fixes:

  • #14966 Error when clicking enrichment button after adding an external reference
  • #14854 History issue / log on add "itself" in creators (now "add untranslated")
  • #14853 Editing a live stream, the form has wrong layout
  • #14809 When doing top right import, dialog is not closable by clicking elsewhere or using escape
  • #14539 Dashboard configuration export (JSON) fails with INTERNAL_SERVER_ERROR: "Expected a string but received a Object"
  • #14527 Dashboard: Export fails when a widget contains a dynamic "in regard of" filter
  • #11790 Incorrect redirect after logout when using base_path
  • #10111 Functional dates not always displayed in timelines

Pull Requests:

Read more

Version 6.9.27

17 Mar 17:03
0c00050

Choose a tag to compare

bug fixes

  • #14877 Live Stream Sync: File operations create infinite event loop in bidirectional sync

Pull Requests:

  • [backend] backport of add sha256 to file metadata & use sha256 to check for duplicate upload (#14877) by @JeremyCloarec in #14969

Full Changelog: 6.9.26...6.9.27