Skip to content

Alerta

v9.1.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 2mo Alerting & Incidents
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

alerta api-server mongodb monitoring postgresql

Summary

AI summary

Feature-rich release adding alert counters, CAS authentication, LDAP improvements, SMTP SSL skip option, and environment pagination. Multiple security bugfixes including SQL injection prevention and self-update endpoint restriction.

Security Fixes

  • Restrict self-update endpoint to allowlisted fields
  • Parameterize Postgres query parser for SQL injection prevention

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Alerta

Get notified when new releases ship.

Sign up free

About Alerta

Alerta monitoring system

All releases →

Related context

Beta — feedback welcome: [email protected]