RSS feed for all product releases
RSS feed for Mividas Installer only

[2.0.0] - 2026-09-11

The appliance moves to Debian 13, the largest platform update the product has had.

It is a new foundation for the whole system: a 6.12 long-term-support kernel carrying years of scheduler, memory-management and I/O work, Python 3.13, OpenSSH 10, and an OpenSSL 3 whose provider architecture is what modern cryptographic policy is built on. Years of accumulated security fixes arrive in a single step, and the platform is supported into the next decade.

Existing installations upgrade in place, from the web interface, keeping their data, machine identity and certificates — no reinstall and no migration.

Added

  • Upgrade the appliance to Debian 13 from the dashboard. Hosts on Debian 10, 11 and 12 are all carried through, rebooting as often as they need to, with the progress, the log and the final outcome in the web console — and a notice that says up front that the server reboots itself and cannot be put back without a backup or snapshot

  • STIG hardening and FIPS provider mode are listed under Security below. Both require a separate license — contact us for more information

  • Upgrade the PostgreSQL databases of managed components, and the Installer’s own, to version 16. The upgrade runs from the maintenance page with a confirmation step, and is offered only where the running version and the component’s image make it applicable

Security

STIG and FIPS provider mode

  • Warn at login when a host is set up for FIPS provider mode but is not actually running it, and repair it on the next configuration pass — keeping the mode where the module can be re-sealed, and returning to the standard cryptographic configuration where it cannot. A host in that state fails every cryptographic call, so it stops accepting new SSH sessions and cannot be logged into to be repaired by hand

  • FIPS provider mode is now delivered as a package carrying its own module, so nothing has to re-seal a module the distribution owns. It is installed on Debian 13 only, and a host that is upgraded rather than rebuilt picks it up on its next package run

  • The password required when the Installer is first opened follows the DISA baseline on a host reporting FIPS or STIG: fifteen characters across all four character classes. Everywhere else the previously configured requirements apply, unchanged

  • Remind operators in the console wizard’s compliance menu that the STIG login banner is theirs to supply, and name the files to edit for SSH and for console logins

  • The STIG login banner is no longer bundled, since the required wording differs per deployment. The file ships empty with SSH already pointed at it — supply your organisation’s own text

[1.8.21] - 2026-09-10

Added

  • Run more than one copy of a component’s background and web services, each sized from the memory the Installer allocated to that component rather than from a fixed figure in its definition. A component has to ask for this, so existing installations are unaffected

  • Show real progress for long-running operations in the web console: numbered steps and a progress bar during a deploy, an upload progress bar and an immediate acknowledgement when importing an offline bundle, and a clear warning when a run was cut short rather than a partial log that looks like a finished one

  • Show “Waiting for the database” or “Upgrade in progress” while the database is still starting or migrations are running during an upgrade, instead of a server error page. The pages refresh themselves, so a tab left open recovers on its own

  • Keep the “settings changed — needs deploy” reminder until the component is actually deployed. It is now recorded per component, so it survives logout, appears in other browsers, names which components are waiting, and stays up if a deploy fails

  • Replace a VM’s operating system disk while keeping its data, machine identity and SSH host keys: attach a disk written from a normal image, boot it, and it adopts the existing installation instead of coming up as a stranger on empty storage. New cli os commands cover the status, relabel and adopt steps, and can create the separate data disk on a VM that does not have one

  • Collect docker service and host status every 15 minutes into the existing log collection, so a support bundle gathered after an incident shows what was running when the problem happened — including previous task states and the error a rescheduled task died with — not only what is running now

  • Add cli traefik prune-certs to clear unloadable certificates from the load balancer and Installer proxy TLS configuration

  • Report the host’s time synchronisation and warn when it has none: the console wizard’s status view shows the configured time sources and whether the clock is actually set, and the dashboard warns when the host has no time source at all. A clock that has quietly stopped being set breaks TLS in ways that look like anything but a clock

  • Show what the Installer is running on beside the active license: CPUs, memory, uptime, the Installer version, and the host operating system, kernel and container runtime. Each row appears only where the host can answer for it, so the page still renders when the container runtime cannot be reached

  • Turn on certificate revocation checking for outbound TLS, with the coverage in view: revocation lists are now collected for intermediate authorities as well as roots, and the Installer reports how many issuers are covered, uncovered and failing. It is off by default, because a connection is refused outright when an issuer has no current list

  • Choose where audit records go: kept on the host, sent to the system log, or sent to an audit collector. The host’s own copy is the default, since the other two cost something on every event and neither is worth paying for by accident

  • Check that a SAML identity provider’s metadata address is reachable when it is saved. The Installer’s own SAML refuses the save, since a mistake there locks the operator out of the server they are configuring; a component’s SAML records a warning instead, because the provider is as likely as anything else to be undeployed when the form is filled in

  • Check the strength of the password chosen when the Installer is first opened, and list the requirements above the field

  • Stream an Installer backup straight over SSH: cli installer backup writes the archive to standard output and cli installer restore reads it back, matching the other backup commands

  • Report a run whose output has stopped arriving as stopped, rather than leaving the console spinning. A dropped connection and a slow step look the same from inside the page, so a run that had already ended went on looking active

  • Offer the host’s own name back in the console wizard’s hostname prompt rather than opening empty, where an operator confirming the name they already had had to retype it in full

  • Report the deployed message broker version, and tell when a previous broker has been drained and can be shut down. A broker that cannot be reached is never reported drained, since stopping it then would discard whatever it still holds

Fixed

  • Fix an Installer upgrade appearing to hang and then ending on “Giving up”. It now waits long enough for the host to pick the request up, reads the host’s upgrade log from a path it can see, and reports an error rather than spinning once it does time out

  • Fix a deploy looking stalled because an internal proxy container was removed mid-deploy, which left the web interface unable to show progress until the stack recreated it

  • Fix “value too long” errors on installations that were upgraded through 1.8.12 or 1.8.13, where some encrypted database columns were left at their original width. A migration widens them; fresh and healthy installations are untouched

  • Keep the Installer usable when its database connection pool is down, by connecting to the database directly and returning to the pool automatically once it is back

  • Fix a Portal or Core connection test reporting success when the far end had rejected it. A rejected API key, a host that does not answer the booking API, and other errors are now reported separately

  • Fix a change to the Installer’s time zone not taking effect until it was restarted

  • Fix container names not matching, and deploy status output going missing, on installations running plain compose rather than swarm

  • Skip the post-deploy database tuning step for the Outlook Add-in, which has no database of its own

  • Stop trying to fetch an image that offline installations cannot reach, which only filled the log with errors

  • Fix a package installation looping while holding the package manager’s lock, which left the VM needing a reboot before any further upgrade or configuration change would run. Package operations are now fully non-interactive, keep existing configuration files, never start on a package the offline bundle does not carry, finish an interrupted transaction automatically, and release a lock held by a dead process after an hour

  • Fix a TLS certificate that cannot be loaded taking HTTPS down altogether, including the Installer’s own interface on :8999 — which is where an operator would go to repair the certificate. The broken entry is dropped so the load balancer falls back to its built-in certificate, and it returns once the certificate is fixed

  • Fix the console wizard restarting in a loop on a VM that has no serial port, which on a hardened host was enough on its own to overflow the kernel’s audit queue and leave the machine unresponsive

  • Audit logs now have a single owner, which keeps the live file and two rotations and compresses everything older

  • Fix the console wizard’s time server prompt opening empty whatever was configured, where confirming it then left a statically addressed host with no time source at all. This matches the reports of time synchronisation stopping after the move to chrony

  • Fix a host whose name was set at first boot rather than through the wizard logging a resolution failure on every administrative command, as both a journal record and an audit event

  • Fix the dashboard hiding host warnings and the new-version notice on a server with no products deployed yet, which is the server most likely to need them

  • Fix a deploy reporting the wrong number of running containers, by counting the copies that are wanted and the ones still starting rather than every task the stack has ever had

  • Fix the log viewer failing to start where its container could not write temporary files

  • Fix the host upgrade log losing everything written from inside a container, so an upgrade that failed there left no record of why

Changed

  • Saving a Portal or Core connection that does not answer is now a warning rather than a refused save, since the component being pointed at is routinely not deployed yet. The check re-runs in the background and the warning clears on its own once the connection works

Security

  • Harden the directories that containers mount from the host: they are root-owned, sticky and closed to other accounts. The hardening is re-applied at boot and after each deploy

  • Audit records are retained for a week rather than four days, by excluding two kinds of daemon churn that accounted for almost all of the volume

  • Update VM kernel 6.1.177 → 6.1.180 (cloud), delivering the latest Debian LTS kernel security fixes, including local use-after-free / privilege-escalation fixes (e.g. posix-cpu-timers exec race CVE-2026-64560 and cgroup writeback CVE-2026-64378) and a virtio-net receive-path fix (CVE-2026-64552). Requires a reboot.

  • Upgrade the Installer container with the Debian 13.6 security batch — libpq5 (PostgreSQL client), util-linux / login, cryptography, pyasn1, soupsieve, sqlparse, liblzma5 and OpenSSL.

  • Related CVEs: GHSA-537c-gmf6-5ccf, CVE-2026-6464, CVE-2026-6471, CVE-2026-6473, CVE-2026-14662, CVE-2026-14664, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670, CVE-2026-14671, CVE-2026-14677, CVE-2026-14679, CVE-2026-14680, CVE-2026-15741, CVE-2026-15742, CVE-2026-16239, CVE-2026-18408, CVE-2026-19385, CVE-2026-49476, CVE-2026-49477, CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-54284, CVE-2026-59884, CVE-2026-59885, CVE-2026-59886, CVE-2026-59893, CVE-2026-63829, CVE-2026-64352, CVE-2026-64375, CVE-2026-64378, CVE-2026-64530, CVE-2026-64531, CVE-2026-64552, CVE-2026-64560, CVE-2026-69247, CVE-2026-69249, CVE-2026-71491

[1.8.20] - 2026-07-30

Fixed

  • Fix docker container isolation issue that causes timeouts after 30 minutes when running Core and Portal on the same VM
  • Fix grub bootloader EFI + Secure Boot issue during grub upgrade

Security

  • Update VM kernel 6.1.176 → 6.1.177 (cloud), delivering the latest Debian LTS kernel security fixes. Includes a local privilege-escalation fix in the KEYS/keyctl subsystem (CVE-2026-63824). Requires a reboot.
  • Upgrade grub2 boot loader (2.06-3~deb11u6 → ~deb11u7) — hardens the boot chain against crafted-filesystem parsing bugs (heap/integer overflows in the HFS/HFS+/UDF/squash4/JFS/BFS/UFS/tar/JPEG parsers and two lockdown bypasses). Boot-time/local integrity hardening, not network-reachable.
  • Upgrade xz-utils / liblzma5 (decompression denial-of-service hardening)
  • Related CVEs: CVE-2024-45782, CVE-2025-0624, CVE-2025-0678, CVE-2025-0689, CVE-2025-1125, CVE-2026-53157, CVE-2026-53366, CVE-2026-63795, CVE-2026-63824, CVE-2026-63830, CVE-2026-64191

[1.8.19] - 2026-07-12

Fixed

  • Fix upgrade delay issues from some versions where you had to wait for the installer to finish or re-press upgrade multiple times

[1.8.18] - 2026-07-09

Added

  • Add support to enable only FIPS-validated HTTPS crypto algorithms in load balancer
  • Preparation for upcoming STIG hardening and FIPS support (separate license required) - contact us for information
  • Add support for docker userns rewrite (see "Security below")

Fixed

  • Force apply VM upgrades after updating Installer if the first run fails
  • Ignore NXDOMAIN errors when resolving hostnames for health check
  • Filter auditd rules before applying file monitoring to only include rules that are relevant to the current system
  • Fix resetting installer password using cli component passwd without specifying username
  • Fix installer password after database restore

Security

  • Upgrade VM kernel from 5.10 to 6.1 (cloud), delivering the accumulated Debian kernel security fixes. This includes the full fix for CVE-2026-46300 ("Fragnesia"), for which 1.8.17 only shipped an interim mitigation. Requires a reboot.

  • Upgrade openssl, libssl1.1, libgnutls30, krb5 (libgssapi-krb5-2, libk5crypto3, libkrb5-3, libkrb5support0), sudo and hyperv-daemons

  • Related CVEs: CVE-2022-50552, CVE-2023-53596, CVE-2025-10263, CVE-2025-21863, CVE-2025-22107, CVE-2025-38129, CVE-2025-38584, CVE-2026-6473, CVE-2026-6477, CVE-2026-6478, CVE-2026-23099, CVE-2026-23372, CVE-2026-23397, CVE-2026-31399, CVE-2026-31452, CVE-2026-31455, CVE-2026-31485, CVE-2026-31489, CVE-2026-31580, CVE-2026-31607, CVE-2026-31627, CVE-2026-31657, CVE-2026-31659, CVE-2026-31686, CVE-2026-31696, CVE-2026-31720, CVE-2026-31747, CVE-2026-31748, CVE-2026-31759, CVE-2026-31787, CVE-2026-31788, CVE-2026-35535, CVE-2026-43015, CVE-2026-43027, CVE-2026-43040, CVE-2026-43114, CVE-2026-43196, CVE-2026-43281, CVE-2026-43328, CVE-2026-43386, CVE-2026-43426, CVE-2026-43427, CVE-2026-43449, CVE-2026-43450, CVE-2026-43453, CVE-2026-43458, CVE-2026-43503, CVE-2026-45866, CVE-2026-45867, CVE-2026-45879, CVE-2026-45885, CVE-2026-45914, CVE-2026-45916, CVE-2026-45920, CVE-2026-45936, CVE-2026-45984, CVE-2026-45994, CVE-2026-46022, CVE-2026-46033, CVE-2026-46047, CVE-2026-46064, CVE-2026-46191, CVE-2026-46243, CVE-2026-46285, CVE-2026-46294, CVE-2026-46300, CVE-2026-46301, CVE-2026-52914, CVE-2026-52943, CVE-2026-52972, CVE-2026-53002, CVE-2026-53130, CVE-2026-53266, CVE-2026-53294, CVE-2026-53296

  • Use SCRAM-SHA-256 for authentication to internal PostgreSQL (database server is still not network accessible)

  • Isolate docker containers further when running in shared networks (e.g. traefik load balancer ingress)

  • Add support for docker userns rewrite for increased security hardening using cli docker enable-userns. (beta) Note: this will rewrite all existing data on disk. Make sure to have a full VM backup before trying this in an existing instance

Changed

  • Decrease DNS timeout and retries for a better experience in environment with enabled DNS recursion but no available network paths

[1.8.17] - 2026-05-22

Fixes

  • Fix changing static IP for second NIC using onboard wizard
  • Display available IPs in select box in Server network settings

Security

  • Update linux kernel
  • Related CVEs: CVE-2026-46333, CVE-2026-46300
  • Applies mitigation for CVE-2026-46300 ("Fragnesia") until a new kernel is released
    printf 'install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n' | sudo tee /etc/modprobe.d/dirtyfrag.conf
    if sudo lsmod | egrep -q 'esp4|esp6|rxrpc'; then sudo rmmod esp4 esp6 rxrpc ; echo 1 | sudo tee /proc/sys/vm/drop_caches; fi

[1.8.16] - 2026-05-09

Security

  • Update linux kernel - includes fix for CVE-2026-43284, CVE-2026-43500 ("Dirty Frag")
  • Related CVEs: CVE-2026-43284, CVE-2026-43500

[1.8.15] - 2026-05-01

Fixed

  • Stop printing running status if deploying a mix of active components and "Uninstalled but keep data" ones

Security

  • Update linux kernel - includes fix for CVE-2026-31431 (Copy Fail). This update requires a reboot.
  • Related CVEs: CVE-2026-31431
  • Mividas components do not permit arbitrary user code execution by default, but we nonetheless recommend upgrading as soon as possible to reduce the attack surface exposed by any as-yet-unknown vulnerabilities

[1.8.14] - 2026-04-30

Added

  • Add support to reboot VM from web gui
  • Do DNS resolution health check on web gui start screen
  • Add view to display the largest database tables sizes for installed components from web gui
  • Add support to set private key type when generating new certificates/CSRs
  • Add CLI-command to clear redis-data for a container in case of corruption cli component redis_clear
  • Improved handling for flushing write caches in data layer during hypervisor snapshot event

Fixed

  • Fix cli db dump-command
  • Fix serialization of encrypted SAML private keys
  • Fix issue installing Core v4.1 on first generation VMs (~2019)

Security

  • Add beta-support for changing container runtime to crun instead of runc to workaround CVE-2025-31133, CVE-2025-52565, CVE-2025-52881 (although these vulnerabilities are not really applicable for Mividas appliance with pre-screened images, only for generic container platforms during untrusted image startup)
  • Upgrade bind9-host, bind9-libs, containerd, django, hyperv-daemons, libpng16-16, libxml, libssl1.1, libsystemd0, libudev1, linux-image, openssh-client, openssh-server, openssh-sftp-server, openssl, python3-urllib3, python3.9, systemd, systemd-sysv, systemd-timesyncd, udev
  • Related CVEs: CVE-2022-37454, CVE-2024-25621, CVE-2025-13836, CVE-2025-22121, CVE-2025-38201, CVE-2025-39702, CVE-2025-57833, CVE-2025-64458, CVE-2025-64459, CVE-2025-68366, CVE-2025-68724, CVE-2025-69419, CVE-2025-69421, CVE-2025-71091, CVE-2025-71093, CVE-2025-71123, CVE-2025-8194, CVE-2026-1299, CVE-2026-1519, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-21441, CVE-2026-22695, CVE-2026-22801, CVE-2026-22998, CVE-2026-23001, CVE-2026-23074, CVE-2026-23083, CVE-2026-23209, CVE-2026-23268, CVE-2026-23408, CVE-2026-23410, CVE-2026-23411, CVE-2026-23949, CVE-2026-24049, CVE-2026-25646, CVE-2026-26007, CVE-2026-27459, CVE-2026-29111, CVE-2026-30922, CVE-2026-33416, CVE-2026-33636, CVE-2026-3497, CVE-2026-41066, CVE-2026-6100

[1.8.13] - 2026-01-15

Added

  • Add support for including latest stable Installer in offline bundle by adding ?include_installer=1 to browser URL before pressing "Export offline bundle"
  • Add support to configure SNMPv3 authentication from wizard

Fixed

  • Fix SNMP configuration in wizard
  • Fix problem where offline installations stops on "missing offline bundle"-error. To upgrade Installer, import bundle and either reboot or run upgrade command from cli wizard
  • Fix displaying EULA in offline mode

Security

  • Update SSH cryptographic algorithms to modern standards

Changed

  • Display warning indicator next to expired Intermediary CA certificates
  • Change help message about maximum length for SMS sender option

[1.8.12] - 2025-12-22

Added

  • Pass information about any trial licenses to each component

Fixed

  • Match pre-released offline versions of the same component if license has access to multiple channels
  • Verify connection for any Identify to Portal API-connections

Security

  • Enable HSTS-headers for Installer port and, with short duration, any non-bound FQDNs
  • Patch Django for CVE-2025-64460, CVE-2025-133722
  • Upgrade libpng16-16, urllib3, cryptography, libssl
  • Related CVEs: CVE-2025-64720, CVE-2025-65018, CVE-2025-66293, CVE-2025-66418, CVE-2025-66471

Changed

  • Use custom logic for disk cleanup in web gui to prevent docker from removing images used by components
  • Enable basic syntax highlighting for log output

[1.8.11] - 2025-10-21

Fixed

  • Fix EC private key import
  • Stop generating certificates for uninstalled components that are kept in list

Security

  • Upgrade bind9-host, bind9-libs, hyperv-daemons, libfastjson4, libgnutls30, libpam-modules, libpam-modules-bin, libpam-runtime, libpam0g, libxml2, libxslt1.1, linux-image-5.10.0-35-cloud-amd64, linux-image-cloud-amd64, open-vm-tools, qemu-guest-agent, sudo
  • Related CVEs: CVE-2025-40778, CVE-2025-40780, CVE-2025-8677, CVE-2022-21546, CVE-2023-52935, CVE-2024-26739, CVE-2025-37798, CVE-2025-37819, CVE-2025-37890, CVE-2025-37913, CVE-2025-37914, CVE-2025-37915, CVE-2025-37923, CVE-2025-37927, CVE-2025-38000, CVE-2025-38001, CVE-2025-38052, CVE-2025-38075, CVE-2025-38079, CVE-2025-38084, CVE-2025-38085, CVE-2025-38095, CVE-2025-38100, CVE-2025-38107, CVE-2025-38108, CVE-2025-38112, CVE-2025-38115, CVE-2025-38138, CVE-2025-38146, CVE-2025-38147, CVE-2025-38160, CVE-2025-38177, CVE-2025-38180, CVE-2025-38181, CVE-2025-38184, CVE-2025-38197, CVE-2025-38200, CVE-2025-38206, CVE-2025-38212, CVE-2025-38313, CVE-2025-38324, CVE-2025-38332, CVE-2025-38350, CVE-2025-38352, CVE-2025-38386, CVE-2025-38399, CVE-2025-38424, CVE-2025-38439, CVE-2025-38457, CVE-2025-38459, CVE-2025-38464, CVE-2025-38466, CVE-2025-38474, CVE-2025-38477, CVE-2025-38498, CVE-2025-38569, CVE-2025-38572, CVE-2025-38666, CVE-2025-38718, CVE-2025-39817, CVE-2025-39824, CVE-2025-39828, CVE-2025-39841, CVE-2020-12762, CVE-2025-32988, CVE-2025-32990, CVE-2025-6020, CVE-2025-49794, CVE-2025-49796, CVE-2025-6021, CVE-2025-7424, CVE-2025-41244, CVE-2024-7409, CVE-2025-32462

Changed

  • Drop ICMP timestamp request packages

[1.8.10] - 2025-06-18

Added

  • Try pinging host using different packet sizes in network tools to help find MTU-issues
  • Add settings to enable SAML for backend admin against Mividas Identify v1.1.0+
  • Add support to disable exporting private key of self signed certificates from UI.
  • Add support to redact IP addresses from log files

Fixed

  • Ping command in network tools
  • Delay initial boot to give NTP some time to sync before generating certificates based on current time
  • Validate certificate/private key combination when updating one at the time
  • Skip importing already existing CAs during full chain imports
  • Fix until-filter for docker service logs
  • Fix false positive message about running a pre-release version of Installer on upgrade page
  • Fix SAML group membership filter - it was previously not applied correctly.
  • Fix using offline XML metadata for SAML
  • Fix parsing log lines with timestamps without year if the date is from last year
  • Fix redeploying all components using CLI
  • Fix cleanup of audit logs for installations with lots of rotated files
  • Fix SNMP configuration in wizard
  • Fix changing password using cli component passwd
  • Clear any corrupt docker gzipped log files to prevent parse errors during report
  • Fix file permission on VM state file to allow status/warning messages to be seen in Installer on all installation
  • Collect log from each docker service task individually to workaround docker bug which sometimes crashes dockerd when trying to pull logs from failed tasks
  • Fix printing syslog when having HTTP proxy enabled

Security

  • Fix SAML group membership filter - it was previously not applied correctly. Mitigation for older versions is to limit logins in the idP
  • Upgrade Installer dependencies: gunicorn, libexpat1, libxml2
    • Related CVEs: CVE-2024-6827, CVE-2024-45491, CVE-2024-45492, CVE-2024-56171, CVE-2024-56171
  • Upgrade VM libraries: bind9-libs, busybox, docker.io, hyperv-daemons, libcap2, libfreetype6, libglib2.0-0, libperl5.32, libxml2, libxslt1.1, linux-image-cloud-amd64, perl-base, perl-modules-5.32, python3.9, vim-common, vim-tiny, xxd
    • Related CVEs: CVE-2024-11187, CVE-2022-48174, CVE-2021-28831, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386, CVE-2024-41110, CVE-2024-47685, CVE-2024-38538, CVE-2024-38588, CVE-2024-44940, CVE-2024-46853, CVE-2024-46854, CVE-2024-46858, CVE-2024-46865, CVE-2024-47701, CVE-2024-47742, CVE-2024-47748, CVE-2024-49860, CVE-2024-49882, CVE-2024-49883, CVE-2024-49884, CVE-2024-49889, CVE-2024-49983, CVE-2024-49995, CVE-2024-50033, CVE-2024-50036, CVE-2024-50055, CVE-2024-50083, CVE-2024-50115, CVE-2024-50127, CVE-2024-50131, CVE-2024-50193, CVE-2024-50262, CVE-2024-50278, CVE-2024-50279, CVE-2024-50301, CVE-2024-53057, CVE-2024-53096, CVE-2024-53099, CVE-2024-53103, CVE-2024-53141, CVE-2024-53142, CVE-2024-53227, CVE-2024-56601, CVE-2024-56606, CVE-2024-56615, CVE-2024-56631, CVE-2024-56642, CVE-2024-56650, CVE-2024-56662, CVE-2024-56672, CVE-2024-56766, CVE-2024-57951, CVE-2025-21648, CVE-2025-21687, CVE-2025-21692, CVE-2023-2603, CVE-2025-27363, CVE-2024-52533, CVE-2020-16156, CVE-2023-31484, CVE-2021-29921, CVE-2015-20107, CVE-2020-10735, CVE-2021-28861, CVE-2021-3737, CVE-2022-0391, CVE-2022-42919, CVE-2022-45061, CVE-2023-24329, CVE-2023-6597, CVE-2024-6232, CVE-2024-7592, CVE-2024-9287, CVE-2024-25062, CVE-2024-56171, CVE-2025-24928, CVE-2025-27113, CVE-2024-55549, CVE-2025-24855, CVE-2023-49083, CVE-2023-43804, CVE-2021-3872, CVE-2021-4019, CVE-2021-4173, CVE-2021-4187, CVE-2022-0261, CVE-2022-0351, CVE-2022-0359, CVE-2022-0361, CVE-2022-0392, CVE-2022-0417, CVE-2022-0572, CVE-2022-1616, CVE-2022-1785, CVE-2022-1897, CVE-2022-1942, CVE-2022-2000, CVE-2022-2129, CVE-2022-2304, CVE-2022-3099, CVE-2022-3134, CVE-2022-3324, CVE-2022-4141, CVE-2023-0054, CVE-2023-2610, CVE-2023-4738, CVE-2023-4752, CVE-2023-4781, CVE-2023-5344, CVE-2024-22667

Changed

  • Upgrade cloud-init to 22.4.2 for new installations
  • Sort service names in log view
  • Link to certificate page to manage certificates instead of displaying inline file upload inputs in forms
  • Reload certificate lists in select boxes automatically
  • Use correct help text for Identify API-field, add more information about SAML and LDAP
  • Display message about necessary reboot during uninstall if containerd is stuck
  • Display logs full width in page, stream output in chunks for service status and log lines
  • Use service task id for the instance of each log entry in log output

[1.8.9] - 2024-10-09

Added

  • Add function to clean up old container images from the web gui server menu

Fixed

  • Fix HTTP -> HTTPS redirect
  • Fix building certificate chain during deploy when Intermediate but not Root CA is included in certificate file
  • Store subject of Intermediate CA as name in the database, instead of Issuer, when importing CA-chain
  • Always use service definition for the correct version when installing components in offline mode
  • Fix conflicts when pinning image used in multiple components (e.g. postgres) in offline mode
  • Abort offline installation in case of missing offline bundles
  • Fix audit log max file number for new installation
  • Fix upgrading specific Installer version from CLI
  • Save snapshot queue reset-script in filesystem on upgraded installations
  • Don't try to parse SAML claim names in URL-format as search+replace fields
  • Use updated license flags as soon as possible, instead of after each deploy

Security

  • Upgrade bind9-host, bind9-libs, e2fsprogs, hyperv-daemons, libcom-err2, libexpat1, libext2fs2, libgssapi-krb5-2, libk5crypto3, libkrb5-3, libkrb5support0, libsqlite3-0, libss2, libsystemd0, libudev1, libxml2, linux-image-5.10.0-30-cloud-amd64, linux-image-cloud-amd64, logsave, python3-pkg-resources, python3-setuptools, runc, shim-unsigned, systemd, systemd-sysv, systemd-timesyncd, traefik, udev
  • Related CVEs: CVE-2021-36690, CVE-2022-1304, CVE-2022-2309, CVE-2022-43945, CVE-2022-48733, CVE-2023-27561, CVE-2023-28642, CVE-2023-40547, CVE-2023-40548, CVE-2023-50387, CVE-2023-50868, CVE-2023-52425, CVE-2023-7104, CVE-2024-1737, CVE-2024-1975, CVE-2024-27397, CVE-2024-36971, CVE-2024-36978, CVE-2024-37370, CVE-2024-37371, CVE-2024-38381, CVE-2024-38555, CVE-2024-38577, CVE-2024-38627, CVE-2024-39480, CVE-2024-39487, CVE-2024-4076, CVE-2024-40958, CVE-2024-41000, CVE-2024-41040, CVE-2024-41046, CVE-2024-41049, CVE-2024-41070, CVE-2024-41087, CVE-2024-41090, CVE-2024-41091, CVE-2024-42148, CVE-2024-42284, CVE-2024-42285, CVE-2024-42301, CVE-2024-42302, CVE-2024-42313, CVE-2024-43882, CVE-2024-44974, CVE-2024-44987, CVE-2024-44998, CVE-2024-44999, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-46738, CVE-2024-46740, CVE-2024-46743, CVE-2024-46744, CVE-2024-46747, CVE-2024-46782, CVE-2024-46800, CVE-2024-46844, CVE-2024-6345

Changed

  • Require confirmation when upgrading to another major version
  • Stop writing cron events to audit logs
  • Automatically reset expired Swarm-certificate for VMs that have been shutdown too long
  • Pre-fill domain names in CSR-form
  • Display timezone for log viewer fields
  • Include digest information for each image in offline bundle-export
  • Use CONNECT with HTTP/1.1 including Host-header when using HTTP(S) proxy

[1.8.8] - 2024-07-01

Fixed

  • Increase timeout in load balancer (traefik) CVE mitigation that caused issue with large file uploads
  • Truncate name of container secret if name of instance is too long

[1.8.7] - 2024-05-29

Added

  • Add script to restore scheduled tasks after VM snapshot/backup-restore

Fixed

  • Fix intermittent error message on dashboard about acquiring lock
  • Fix SRV-lookup for LDAP servers
  • Fix syntax of AD LDAP filter example in network tools
  • Hide validation error alert for unfilled optional forms during installation
  • Fix resetting fallback user password using sudo cli component passwd
  • Fix file permissions in upgrade container
  • Freeze auditd rules for existing installations
  • Fix starting ssh directly on boot during initial installation

Security

  • Upgrade bsdutils, django, dnspython, fdisk, gunicorn, less, libblkid1, libexpat1, libfdisk1, libmount1, libsmartcols1, libuuid1, linux-kernel, gunicorn, mount, paramiko, sqlparse, traefik, tzdata, util-linux
  • Related CVEs: CVE-2021-37600, CVE-2023-29483, CVE-2022-48624, CVE-2024-32487, CVE-2023-48795, CVE-2023-52425, CVE-2024-1135, CVE-2024-24680, CVE-2024-28085, CVE-2024-4340, CVE-2024-2961, DLA-3788-1

Changed

  • Use pool for database connections
  • Upgrade load balancer (traefik) to v2.11
  • Use postgresql 16 for new installations of both Installer and components
  • Improve cache handling for SAML metadata. Add HTTP PRoxy-support
  • Set upper process limit for containers
  • Disable routing for internal load balancer network on new installations

[1.8.6] - 2024-03-22

Fixed

  • Fix locking issue during metadata update that sometimes causes long timeouts and overuse of database connections after enough user actions without restart. Run sudo cli installer upgrade from SSH to upgrade if that happens, or restart the server
  • Fix deploy of LDAPAdmin when using certificate
  • Fix displaying certificate error message on screen
  • Fix LDAP username attribute when using search+replace

Security

  • Upgrade libuv1
  • Related CVEs: CVE-2024-24806

[1.8.5] - 2024-03-05

Added

  • Resolve LDAP servers in network tools test. Try to verify SSL-connection
  • Add support for filtering log with until-filter
  • Add support to disable SAML-login for installer using "cli installer disable_saml" and "cli installer restore_saml"

Fixed

  • Fix fetching syslog in Logs-view
  • Don't enable SAML SLO if upgrading from 1.8.3 or earlier
  • Use more conservative upscaling of services to decrease risk of Out of memory-errors
  • Increase global max memory limit to prevent VM scaling to increase potential memory usage too much in case of using 12+ GB of RAM
  • Remove external version check-request from internal load balancer
  • Fix unnecessary restarts of Installer-component

Security

  • Upgrade hyperv-daemons, libglib2.0-0, libgnutls30, libperl5.32, linux-image-5.10.0-26-cloud-amd64, linux-image-cloud-amd64, perl-base, perl-modules-5.32, runc
  • Related CVEs: CVE-2023-29499, CVE-2023-35827, CVE-2023-46813, CVE-2023-47038, CVE-2023-5178, CVE-2023-5717, CVE-2023-6040, CVE-2023-6531, CVE-2023-6817, CVE-2023-6931, CVE-2023-6932, CVE-2024-0567, CVE-2024-0646, CVE-2024-1086, CVE-2024-2162,

Changed

  • Set flag in SAML SP-metadata about wanting assertions signed
  • Use streaming console output for long-lasting commands
  • Change console log-format
  • Refresh session expiry on each request
  • Include extra information about running services in log output
  • Use logrotate for auditd-logs
  • Limit redundant journald-log size

[1.8.4] - 2023-12-31

Added

  • Add support for SAML login. See /saml/metadata/ for SP metadata.
  • Display EULA in interface
  • Add support to configure remote syslog server from onboarding wizard
  • Add support to enable SNMP monitoring (new installations only for now)
  • Add support to configure remote syslog server from onboarding wizard
  • Add support to enable SNMP monitoring (new installations only for now)

Fixed

  • Fix syntax in example AD LDAP-filter
  • Fix permissions of uploads-folder if containers was started in wrong order
  • Remove log files if log partition is full
  • Fix permissions of uploads-folder if containers was started in wrong order
  • Remove log files if log partition is full
  • Fix sorting of syslog log lines

Security

  • Upgrade django, libnghttp2-14, openssh-client, openssh-server, openssh-sftp-server, libpq5
  • Related CVEs: CVE-2023-44487, CVE-2023-51385, CVE-2021-41617, CVE-2023-46695, CVE-2023-5869

Changed

  • Use license key from uploaded file if both textarea and file is provided at the same time
  • Automatically remove newline and spaces from license key before validation
  • Use more memory for each worker when calculating max number of workers for VM-size
  • Limit memory to max 50% of total VM memory for each service
  • Change OOM score for database-containers
  • Increase swap space for older VM-versions
  • Change OOM score for database-containers
  • Increase swap space for older VM-versions

[1.8.3] - [2023-10-31]

Added

  • Add support to use smtp+tls for SMTP relay
  • Add separate field for required LDAP-group for normal users
  • Add support to set SAML claims to use for user/admin/superuser permission
  • Add support to set SAML username claim, with support for search+replace
  • Add support to force restart of services in log view
  • Display disk space warnings on dashboard
  • Display available Installer/VM-upgrades on dashboard
  • Display if reboot is necessary on dashboard
  • Allow specifying specific Installer version when upgrading from command line
  • Add support to display syslog in web-UI

Fixed

  • Fix updating component reference if converting between licensed products
  • Keep currently installed component version in version select-box if it has been removed from global list
  • Allow disabling SAML signing certificate
  • Don't display certificates belonging to non-deployed components as active
  • Fix update of overwritten dev-versions during deploy in offline mode
  • Fix quoting of special characters in HTTP(S) Proxy authentication
  • Fix system logs rotation-timer
  • Upgrade libseccomp for Debian buster based installations to allow for bookwork based docker-images
  • Fix setting static routes on second NIC if routes is configured later

Security

Upgrade bind9-host, bind9-libs, cpio, curl, hyperv-daemons, libc-bin, libc-l10n, libc6, libcurl4, libjson-c5, libncurses6, libncursesw6, libtinfo6, linux-image-5.10.0-23-cloud-amd64, linux-image-cloud-amd64, locales, ncurses-base, ncurses-bin, open-vm-tools, openssh-client, openssh-server, openssh-sftp-server, qemu-guest-agent

  • Related CVEs: CVE-2021-32292, CVE-2021-38185, CVE-2022-39189, CVE-2023-1989, CVE-2023-20900, CVE-2023-2156, CVE-2023-29491, CVE-2023-3090, CVE-2023-31248, CVE-2023-3268, CVE-2023-3341, CVE-2023-3354, CVE-2023-3389, CVE-2023-3390, CVE-2023-35001, CVE-2023-35788, CVE-2023-3609, CVE-2023-3610, CVE-2023-3611, CVE-2023-3776, CVE-2023-3777, CVE-2023-38408, CVE-2023-4004, CVE-2023-40283, CVE-2023-4128, CVE-2023-4147, CVE-2023-4206, CVE-2023-4207, CVE-2023-4208, CVE-2023-4244, CVE-2023-42753, CVE-2023-4622, CVE-2023-4623, CVE-2023-4911, CVE-2023-4921, CVE-2023-38325, CVE-2023-37920

Changed

  • Automatically retry installation if dockerd times out
  • Hide gunicorn version from Server-header
  • Display additional disclaimer about LDAP user access
  • Revert to old postgres version by default
  • Auto-select only services that are running too many or too few instances in Log view
  • Split CA certificates to multiple rows during import. Don't import duplicates
  • Try to add missing CA-certificates to certificate chain if missing from component certificate file
  • Remove name-field from CA import form. Automatically use subject
  • Compress logs the first rotation
  • Change default LDAP filter to not include disabled users when using AD

[1.8.2] - 2023-07-12

Added

  • Add new TLS cipher option with modern ciphers plus two weak TLS 1.2-ciphers to allow for older firmware of external systems
  • Add support for separate component containing only Mividas Scheduling Portal
  • Allow converting between the same product families e.g. for testing development releases
  • Add support for providing SAML certificate/key pair
  • Add support for selecting TLS-mode and authentication method for external databases

Fixed

  • Don't try to use broken/invalid server default certificate/private key-pairs
  • Use default server timezone when parsing log time filter
  • Fix help text of certificate textbox since adding support for importing encrypted private keys
  • Run log rotation more often for container logs
  • Discard some non-relevant kernel logs during container initialization and teardown
  • Escape http proxy username/password in environment variables
  • Use container service name in syslog
  • Fix database dump using "cli"-command

Security

  • Upgrade curl, linux kernel, openssl, containerd, sudo
  • Upgrade redis, requests, setuptools, sentry-sdk
  • Related CVEs: CVE-2023-25173, CVE-2022-32221, CVE-2023-0179, CVE-2023-1077, CVE-2023-1281, CVE-2023-1829, CVE-2023-1872, CVE-2023-32233, CVE-2023-0361, CVE-2022-29458, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286, CVE-2023-0464, CVE-2023-2650, CVE-2023-22809,
  • Disable network routing for internal container services
  • Set session expiration to 2h
  • Fix issue in error reporting where the system tried to send a report of number of discarded error-messages to a remote server, due to that error reporting was disabled

Changed

  • Change "Mividas Connect" to new product name "Mividas Identify"
  • Remove TLS 1.0 from the most insecure TLS-cipher option
  • Remove LDAP default server settings
  • Pass host VM ca-certificates to containers
  • Use postgres 13 for new installations
  • Move swap file to the same partition as user data
  • Increase default disk size to 200GB, increase log partition-size to 2.5GB
  • Disable unattended installation of subset of debian security upgrades by default

[1.8.1] - 2023-01-15

Added

  • Prepare SAML authentication settings for Mividas Core + Rooms

Fixed

  • Fix home link from product details view
  • Lock postgres version for LDAPAdmin deployed with old version of deploy file
  • Stop re-deploying load balancer on installer upgrade if not necessary
  • Remove warning about missing volumes when removing component
  • Fix service deploy problems when using setting values (e.g. passwords) starting with quotes (")
  • Fix host security update files when upgrading system using offline bundle

Changed

  • Change deploy mode for some shared services to allow Installer upgrades in the future with less downtime
  • Increase number of workers for each component based on available memory
  • Always try to start Installer based on script from the currently running version when using other than the official latest version
  • Encrypt API keys and passwords before saving to database
  • Remove letsencrypt option from certificate config screen
  • Limit access for logs and system files, fix some CIS benchmark warnings, enable console timeout
  • Install host security upgrades just after upgrading Installer, stop docker from potentially being upgraded automatically
  • Discard some recurring kernel log messages about virtual container network interfaces
  • Allow more userdata in cloud-init config

Security

  • Upgrade host packages for grub2, hyperv-daemons, libexpat1, libtasn1-6, libxml2, linux-image-cloud-amd64
  • Related CVEs: CVE-2021-46848, CVE-2022-2601, CVE-2022-3524, CVE-2022-3565, CVE-2022-3594, CVE-2022-3775, CVE-2022-40303, CVE-2022-40304, CVE-2022-4139, CVE-2022-42896, CVE-2022-43680, CVE-2022-4378, CVE-2022-47518, CVE-2022-47519
  • Limit system permissions for load balancer container, run more services with read only root file system

[1.8.0] - 2022-10-20

Added

  • Add support to enable external database from license file
  • Add support to importing and converting binary certificates (beta)
  • Add support to export private keys with encryption, and importing encrypted keys
  • Add support for external redis server
  • Add support for enabling LDAP referral chasing
  • Add support to lookup LDAP servers using SRV records
  • Add more inline documentation for LDAP, SAML and SMS-settings
  • Mark certificates in use in lists
  • Add field for validating SSL handshake against remote port using network tools
  • Validation of database and ldap settings when saving configuration
  • Display information about last component metadata refresh time and add link to force refresh
  • Add CLI command ("cli") with support to, among other things, reset passwords and dump database content
  • Allow ICMP echo requests ("ping")
  • Allow overriding dns when using DHCP
  • Install traceroute
  • Add support for EFI and Secure Boot (beta, new VM installations only)

Fixed

  • Clear certificate existing CA chain when updating public key
  • Fix TLS validation for LDAP test connection
  • Validate line before removing volumes
  • Fix version ordering for x.y.z-dev builds
  • Fix permission to run ping in network tools
  • Fix certificate chain warnings if CA lacks common name information
  • Reset offline mode if online license validation was successful
  • Increase length of ldap filter
  • Remove warning in load balancer logs about SNI host
  • Stop validating values in optional forms marked for deletion
  • Fix offline export if "check for update"-checkbox is not set
  • Fix offline export if any components are marked for uninstallation
  • Remove console log warnings about HostSNI
  • Set static routes after all interfaces are up
  • Install systemd-timesyncd if the initial VM version did not include it
  • Fix returning to menu after setting hostname

Security

  • Upgrade django, openssl, libssl1.1, sqlite3
  • Related CVEs: CVE-2022-28346, CVE-2022-28347, CVE-2022-0778
  • Upgrade bind9-host, bind9-libs, curl, dpkg, grub-common, grub-pc, hyperv-daemons, linux-image-cloud-amd64, libc-bin, libtasn1-6, libssl1.1, openssl, qemu-guest-agent, rsyslog, zlib1g
  • Related CVEs: CVE-2018-13405, CVE-2021-22945, CVE-2021-22946, CVE-2021-30560, CVE-2021-3697, CVE-2021-3999, CVE-2021-4197, CVE-2021-4206, CVE-2021-4207, CVE-2021-46828, CVE-2022-0358, CVE-2022-1012, CVE-2022-1158, CVE-2022-1292, CVE-2022-1353, CVE-2022-1586, CVE-2022-1587, CVE-2022-1652, CVE-2022-1664, CVE-2022-1679, CVE-2022-1729, CVE-2022-1786, CVE-2022-20368, CVE-2022-20422, CVE-2022-20566, CVE-2022-20568, CVE-2022-2068, CVE-2022-22576, CVE-2022-2327, CVE-2022-24903, CVE-2022-2509, CVE-2022-2585, CVE-2022-2588, CVE-2022-2602, CVE-2022-26353, CVE-2022-27404, CVE-2022-27405, CVE-2022-27406, CVE-2022-27666, CVE-2022-27775, CVE-2022-27781, CVE-2022-27782, CVE-2022-2795, CVE-2022-28733, CVE-2022-28734, CVE-2022-29155, CVE-2022-29162, CVE-2022-29581, CVE-2022-29582, CVE-2022-2959, CVE-2022-2977, CVE-2022-30594, CVE-2022-3080, CVE-2022-31676, CVE-2022-3176, CVE-2022-32207, CVE-2022-32250, CVE-2022-34918, CVE-2022-3625, CVE-2022-3635, CVE-2022-36946, CVE-2022-38177, CVE-2022-38178, CVE-2022-40674, CVE-2022-41222, CVE-2022-43750

Changed

  • Only display first certificate chain warning, hide warning if three or more certificates are included
  • Increase log verbosity for ldap tests
  • Set ldap connection timeout
  • List any unknown/not fully uninstalled container services
  • Add pagination and search to certificate lists
  • Use direct API for fetching service logs instead of subprocesses for better performance
  • Escape special characters in authentication to external services
  • Rotate log files more often
  • Increase log file partition size (for new VMs)
  • Decrease console log verbosity
  • Change docker internal IP series to 100.64.10[3-5].0/16 to limit risk of conflicts (new VMs only)
  • Change to GPT based partitions
  • Add docker/-prefix to syslog tag, write container logs to separate files in /var/log/docker/
  • Prepare for support for external syslog servers. Manual configuration should be moved to /etc/rsyslog.d/50-remote.conf
  • Enable SSH login by default for new installation, enable fail2ban to lock logins after too many logins
On This Page
    © Mividas Video Solutions AB 2026