Skip to content

Releases: Cacti/cacti

v1.2.28

07 Oct 00:42
Compare
Choose a tag to compare

Release of Cacti 1.2.28

Thank you everyone who are using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests!

Cacti Change Log

  • security #GHSA-49f2-hwx9-qffr: XSS vulnerability when creating external links with the consolenewsection parameter
  • security #GHSA-fgc6-g8gc-wcg5: XSS vulnerability when creating external links with the title parameter
  • security #GHSA-gxq4-mv8h-6qj4: RCE vulnerability can be executed via Log Poisoning
  • security #GHSA-wh9c-v56x-v77c: XSS vulnerability when creating external links with the fileurl parameter
  • issue #5636: When using LDAP authentication the first time, warnings may appear in logs
  • issue #5754: When installing, a replication loop for plugin_realms may occur
  • issue #5759: When installing, remote poller may attempt to sync with other pollers
  • issue #5768: When a Data Query has a space, indexes may not be properly escaped
  • issue #5771: Boost does not always order data source records properly
  • issue #5772: Add IP address to the login audit for successful logins by xmacan
  • issue #5773: Undefined variable error may sometimes occur when dealing with RRD output by MSS970
  • issue #5777: When export to CSV, only the first line of notes is included
  • issue #5780: When rendering forms, missing default value can cause errors
  • issue #5782: Allow hosted content to be executable for the links page
  • issue #5783: When closing database connections, some may linger incorrectly
  • issue #5785: When changing passwords, an infinite loop may occur by ddb4github
  • issue #5790: When using Cacti Daemon, a "Cron out of sync" message may be reported
  • issue #5791: Add ability to filter/sort users by group or last login time
  • issue #5792: When using List View, unable to add Graphs to a Report
  • issue #5797: When using SNMPv3, some devices may show polling issues
  • issue #5802: Limit table conversion to Cacti core tables
  • issue #5806: Fix issues with posix-based kills on Windows
  • issue #5813: When installing, password changes may fail on new installations
  • issue #5814: When using structured RRD folders, permission issues may be flagged incorrectly
  • issue #5823: When unable to locate a valid theme, new default will be Modern
  • issue #5824: Properly cache the data source information for dsstats processing
  • issue #5840: When reindexing, verify all fields may not work as intended
  • feature #5784: Add ability to log database connections/disconnections
  • feature #5796: Add Ping Method where connection refused assumes host is up
  • feature #5819: When displaying graphs, default end time does not show full 24 hour period
  • feature #5825: Add --id to remove_device.php
  • feature #5828: Add Location and Site to Graph List View
  • feature #5830: Add more verbose logging to Boost
  • feature: Update jQuery to 3.7.1
  • feature: Update jQueryUI to 1.14.0
  • feature: Update Purify.js to 3.1.6
  • feature: Update billboard.js to 3.13.0
  • feature: Improve the performance of the repopulation of the poller cache

Reporting Issues

http://www.cacti.net/issues.php

Download Cacti

http://www.cacti.net/download_cacti.php

Download Spine

http://www.cacti.net/spine_download.php

Thanks!
The Cacti Group

v1.2.27

12 May 20:57
b577c29
Compare
Choose a tag to compare

Release of Cacti 1.2.27

Thank you everyone who are using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

IMPORTANT: There have been a number of security issues that have been addressed in this release. It is
advised to upgrade all existing platforms to this release as soon as possibly to avoid possible issues.

Along with the release of Cacti 1.2.27, several plugins have been updated/added so please check out
Thold (v1.8), MacTrack (v4.7) and the new ServCheck (v0.1) on their github repositories.

We would personally like to thank @xmacan for all his efforts, especially with the new ServCheck, as well
as all the users of Cacti who are contributing to the community on GitHub and in the forums. You know who
you are.

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests!

Cacti Change Log

  • security #GHSA-37x7-mfjv-mm7m: Authentication Bypass when using using older password hashes
  • security #GHSA-7cmj-g5qc-pj88: RCE vulnerability when importing packages
  • security #GHSA-cx8g-hvq8-p2rv: RCE vulnerability when plugins include files
  • security #GHSA-gj3f-p326-gh8r: SQL Injection vulnerability when using tree rules through Automation API
  • security #GHSA-grj5-8fcj-34gh: XSS vulnerability when using JavaScript based messaging API
  • security #GHSA-jrxg-8wh8-943x: SQL Injection vulnerability when using form templates
  • security #GHSA-p4ch-7hjw-6m87: XSS vulnerability when reading tree rules with Automation API
  • security #GHSA-rqc8-78cm-85j3: XSS vulnerability when managing data queries
  • security #GHSA-vjph-r677-6pcc: SQL Injection vulnerability when retrieving graphs using Automation API
  • issue #5622: Improve PHP 8.3 support
  • issue #5628: When importing packages via command line, data source profile could not be selected
  • issue #5629: When changing password, returning to previous page does not always work
  • issue #5636: When using LDAP authentication the first time, warnings may appear in logs
  • issue #5638: When editing/viewing devices, add IPv6 info to hostname tooltip
  • issue #5645: Improve speed of polling when Boost is enabled
  • issue #5648: Improve support for Half-Hour time zones
  • issue #5649: Improve support of ping on Windows
  • issue #5655: When user session not found, device lists can be incorrectly returned
  • issue #5660: On import, legacy templates may generate warnings
  • issue #5661: Improve support for alternate locations of Ping
  • issue #5662: Improve PHP 8.1 support for Installer
  • issue #5669: Fix issues with number formatting
  • issue #5677: Improve PHP 8.1 support when SpikeKill is run first time
  • issue #5693: Improve PHP 8.1 support for SpikeKill
  • issue #5696: When using Chinese to search for graphics, garbled characters appear.
  • issue #5701: When importing templates, preview mode will not always load
  • issue #5720: When remote poller is installed, MySQL TimeZone DB checks are not performed
  • issue #5723: When Remote Poller installation completes, no finish button is shown
  • issue #5725: Unauthorized agents should be recorded into logs
  • issue #5726: Poller cache may not always update if hostname changes
  • issue #5727: When using CMD poller, Failure and Recovery dates may have incorrect values
  • issue #5731: Saving a Tree can cause the tree to become unpublished
  • issue #5732: Web Basic Authentication does not record user logins
  • issue #5733: When using Accent-based languages, translations may not work properly
  • issue #5743: Fix automation expressions for device rules
  • issue #5748: Improve PHP 8.1 Support during fresh install with boost
  • feature #5692: Add a device "enabled/disabled" indicator next to the graphs
  • feature #5710: Notify the admin periodically when a remote data collector goes into heartbeat status
  • feature #5716: Add template for Aruba Clearpass
  • feature #5730: Add fliter/sort of Device Templates by Graph Templates

Reporting Issues

http://www.cacti.net/issues.php

Download Cacti

http://www.cacti.net/download_cacti.php

Download Spine

http://www.cacti.net/spine_download.php

Thanks!
The Cacti Group

v1.2.26

24 Dec 02:41
73d9a60
Compare
Choose a tag to compare

Release of Cacti 1.2.26

Thank you everyone who are using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

Please note, with this release there have been a couple of security issues addressed. For more information see the CHANGELOG and GitHub

Finally, Christmas is approaching and hopefully you are all enjoying your rare free time with family and/or friends. The Cacti Team wishes you all the best in this holiday period and have a happy new year!

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests!

Cacti Change Log

  • security #GHSA-xwqc-7jc4-xm73: XSS vulnerability when importing a template file
  • security #GHSA-pfh9-gwm6-86vp: RCE vulnerability when managing links
  • security #GHSA-vr3c-38wh-g855: SQL Injection vulnerability when managing poller devices
  • security #GHSA-wc73-r2vw-59pr: XSS vulnerability when adding new devices
  • security #GHSA-q7g7-gcf6-wh4x: XSS vulnerability when viewing data sources in debug mode
  • security #GHSA-w85f-7c4w-7594: SQL Injection vulnerability when managing SNMP Notification Receivers
  • issue #5464: When viewing data sources, an undefined variable error may be seen
  • issue #5478: Improvements for Poller Last Run Date
  • issue #5481: Attempting to edit a Data Query that does not exist throws warnings and not an GUI error
  • issue #5483: Improve PHP 8.1 support when adding devices
  • issue #5485: Viewing Data Query Cache can cause errors to be logged
  • issue #5489: Preserve option is not properly honoured when removing devices at command line
  • issue #5490: Infinite recursion is possible during a database failure
  • issue #5492: Monitoring Host CPU's does not always work on Windows endpoints
  • issue #5493: Multi select drop down list box not rendered correctly in Chrome and Edge
  • issue #5494: Selective Plugin Debugging may not always work as intended
  • issue #5495: During upgrades, Plugins may be falsely reported as incompatible
  • issue #5496: Plugin management at command line does not work with multiple plugins
  • issue #5502: Improve PHP 8.1 support for incrementing only numbers
  • issue #5503: Allow the renaming of guest and template accounts
  • issue #5514: DS Stats issues warnings when the RRDfile has not been initialized
  • issue #5527: When upgrading, missing data source profile can cause errors to be logged
  • issue #5534: When deleting a single Data Source, purge historical debug data
  • issue #5542: Improvements to form element warnings
  • issue #5554: Some interface aliases do not appear correctly
  • issue #5555: Aggregate graph does not show other percentiles
  • issue #5561: Settings table updates for large values reverted by database repair
  • issue #5564: When obtaining graph records, error messages may be recorded
  • issue #5565: Unable to change a device's community at command line
  • issue #5572: Increase timeout for RRDChecker
  • issue #5573: When viewing a graph, option to edit template may lead to incorrect URL
  • issue #5581: When upgrading, failures may occur due to missing color table keys
  • issue #5583: On installation, allow a more appropriate template to be used as the default
  • issue #5585: When data input parameters are allowed to be null, allow null
  • issue #5586: CSV Exports may not always output data correctly
  • issue #5589: When debugging a graph, long CDEF's can cause undesirable scrolling
  • issue #5590: Secondary LDAP server not evaluated when the first one has failed
  • issue #5602: When adding a device, using the bulk walk option can make version information appear
  • issue #5609: When parsing a Data Query resource, an error can be reported if no direction is specified
  • issue #5612: Database reconnection can cause errors to be reported incorrectly
  • issue #5613: fix returned value if $sau is empty
  • feature #5577: Add Aruba switch, Aruba controller and HPE iLO templates
  • feature #5597: Add OSCX 6x00 templates

Reporting Issues

http://www.cacti.net/issues.php

Download Cacti

http://www.cacti.net/download_cacti.php

Download Spine

http://www.cacti.net/spine_download.php

Thanks!
The Cacti Group

v1.2.25

05 Sep 00:24
Compare
Choose a tag to compare

Release of Cacti 1.2.25

Thank you everyone who are using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

Following on from our previous release, Cacti has been receiving extra eyes across the code base. This has meant a delay in the release of 1.2.25 as we work with various parties to improve Cacti and provide better protection from potential malicious actors.

Windows users can find a beta version of the latest Windows installer via our forum thread http://forums.cacti.net/viewtopic.php?p=292797#p292797 which will be updated as the beta is updated. There has been a major re-working of the installer including having Apache installed using the Windows Service Virtual Account to help improve security, and updated versions of PHP, RRDtool, Net-SNMP. It also introduces a change from MySQL to MariaDB as the default database engine that is installed.

As we focus more work on trying to get 1.3 ready for testing, we have also added extra device packages that can be installed during the normal web installer, or added manually afterwards (see the install/packages folder).

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests!

Cacti Change Log

  • security #GHSA-77rf-774j-6h3p: Protect against Insecure deserialization of filter data
  • security #GHSA-gx8c-xvjh-9qh4: Protect against Cross-Site Scripting vulnerability when creating new graphs
  • security #GHSA-6r43-q2fw-5wrg: Protect against Unauthenticated SQL Injection when viewing graphs
  • security #GHSA-6jhp-mgqg-fhqg: Protect against SQL Injection when saving data with sql_save()
  • security #GHSA-g6ff-58cj-x3cp: Protect against Authenticated command injection when using SNMP options
  • security #GHSA-q4wh-3f9w-836h: Protect against Authenticated SQL injection vulnerability when managing graphs
  • security #GHSA-gj95-7xr8-9p7g: Protect against Authenticated SQL injection vulnerability when managing reports
  • security #GHSA-v5w7-hww7-2f22: Protect against SQL Injection when using regular expressions
  • security #GHSA-4pjv-rmrp-r59x: Protect against Open redirect in change password functionality
  • security #GHSA-rwhh-xxm6-vcrv: Protect against Cross-Site Scripting vulnerability with Device Name when managing Data Sources
  • security #GHSA-24w4-4hp2-3j8h: Protect against Cross-Site Scripting vulnerability with Device Name when administrating Reports
  • security #GHSA-5hpr-4hhc-8q42: Protect against Cross-Site Scripting vulnerability with Device Name when editing Graphs whilst managing Reports
  • security #GHSA-vqcc-5v63-g9q7: Protect against Cross-Site Scripting vulnerability with Device Name when managing Data Sources
  • security #GHSA-9fj7-8f2j-2rw2: Protect against Cross-Site Scripting vulnerability with Device Name when debugging data queries
  • security #GHSA-6hrc-2cfc-8hm7: Protect against Cross-Site Scripting vulnerability with Data Source Name when managing Graphs
  • security #GHSA-hrg9-qqqx-wc4h: Protect against Cross-Site Scripting vulnerability with Data Source Name when debugging Data Queries
  • security #GHSA-r8qq-88g3-hmgv: Protect against Cross-Site Scripting vulnerability with Data Source Information when managing Data Sources
  • security #GHSA-rf5w-pq3f-9876: Protect against Privilege escalation when Cacti installed using Windows Installer defaults
  • issue #2959: When rebuilding the Poller Cache from command line, allow it to be multi-threaded
  • issue #4045: When searching tree or list views, the URL does not update after changes
  • issue #5254: When creating a Data Source Template with a specific snmp port, the port is not always applied
  • issue #5255: When a Data Query references a file, the filename should be trimmed to remove spurious spaces
  • issue #5258: THold plugin may not always install or upgrade properly
  • issue #5259: RRD file structures are not always updated properly, if there are more Data Sources in the Data Template than the Graph Template
  • issue #5263: When reindexing devices, errors may sometimes be shown
  • issue #5272: Boost may loose data when the database server is overloaded
  • issue #5275: Boost can sometimes output unexpected or invalid values
  • issue #5277: Boost should not attempt to start if there are no items to process
  • issue #5279: Rebuilding the poller cache does not always work as expected
  • issue #5282: Host CPU items may not work poll as expected when on a remote data collector where hmib is also enabled
  • issue #5283: When creating new graphs, invalid offset errors may be generated
  • issue #5291: When importing packages, SQL errors may be generated
  • issue #5298: When managing plugins from command line, the --plugin option is not properly handled
  • issue #5299: When automating an install of Cacti, error messages can be appear
  • issue #5300: When performing automated install of a plugin, warnings can be thrown
  • issue #5315: Automation references the wrong table name causing errors
  • issue #5317: Data Source Info Mode produces invalid recommendations
  • issue #5319: Data Source Debug 'Run All' generates too many log messages
  • issue #5323: The description of rebuild poller cache in utilities does not display properly
  • issue #5324: When reindexing a device, debug information may not always display properly
  • issue #5329: Upon displaying a form with errors, the session error fields variable isn't cleared
  • issue #5333: MariaDB clusters will no longer support exclusive locks
  • issue #5336: RRDtool can fail to update when sources in Data Template and Graph Template data sources do not match
  • issue #5338: Compatibility improvements for Boost under PHP 8.x
  • issue #5342: When searching the tree, increase the time before querying for items
  • issue #5347: Device Location drop down does not always populate correctly
  • issue #5354: When viewing Realtime graphs, undefined variable errors may be reported
  • issue #5355: SNMP Uptime is not always ignored for spikekills
  • issue #5356: Improve detection of downed Devices
  • issue #5360: When reporting missing functions from Plugins, ensure messages do not occur too often
  • issue #5364: When starting the Cacti daemon, database errors may be reported when there is no problem
  • issue #5366: When reporting from RRDcheck, ensure prefix is in the correct casing
  • issue #5371: Improve Orphaned Data Source options and display
  • issue #5372: Parsing the PHP Configuration may sometimes produce errors
  • issue #5376: Security processes attempt to check for a user lockout even if there is no user logged in
  • issue #5377: When attempting to edit a tree, the search filter for Graphs remains disabled
  • issue #5381: When reindexing, a Data Source that could be un-orphaned may not always be unorphaned
  • issue #5382: When parsing a date value, there could be more than 30 chars
  • issue #5384: Untemplated Data Sources can fail to update due to lack of an assigned Graph
  • issue #5386: When processing items to check, do not include disabled hosts
  • issue #5390: When saving a Data Source Template, SQL errors may be reported
  • issue #5392: When importing a Template, errors may be recorded
  • issue #5402: Some display strings have invalid formatting that cannot be parsed
  • issue #5403: When filtering with regular expressions, the 'does not match' option does not always function as expected
  • issue #5409: When enabling a plugin, sometimes it can appear as if nothing happens
  • issue #5413: Ensure the Rows Per Page option shows limitations set by configuration
  • issue #5414: Plugins are unable to modify fields in the setting 'Change Device Settings'
  • issue #5417: When reporting emails being sent, ensure BCC addresses are also included
  • issue #5420: Improve compatibility of SNMP class trim handling under PHP 8.x
  • issue #5426: When importing legacy Data Query Templates, the Template can become unusable
  • issue #5427: Provide ability to raise an event when extending the settings form
  • issue #5434: Prevent unsupported SQL Mode flags from being set
  • issue #5439: The DSStats summary does not always display expected values
  • issue #5440: When performing a fresh install, device classification may be missing.
  • issue #5446: Duplication functions for Graph/Template and Data Source/Template do not return and id
  • issue #5447: Duplication of Device Templates should be an API call
  • issue #5450: Unable to convert database to latin1 instead of utf8 if desired
  • issue #5451: When creating Graphs, the process may become slower over time as more items exist
  • issue #5452: When a bulk walk size is set to automatic, this is not always set to the optimal value
  • issue #5453: Update copyright notice on import packages
  • issue #5454: When viewing Orphan Graphs, SQL errors may be reported
  • issue #5457: When reindexing hosts from command line, ensure only one process runs at once
  • issue #5458: When a Data Query has no Graphs, it may not be deletable
  • issue #5459: When duplicating a Graph Template, provide an option to not duplicate Data Query association
  • issue #5460: When duplicating a Data Template errors can appear in the Cacti log
  • issue #5462: When importing a Package, previewing makes unexpected changes to Cacti Templates
  • issue #5466: When enabling boost on a fresh install, an error may be reported
  • issue #5467: Improve compatibility for backtrace logging under PHP 8.x
  • issue #5475: Improve compatibility for Advanced Ping under PHP 8.x
  • feature #5375: Provide new templates for Fortigate and Aruba Cluster to be available during install
  • feature #5393: Provide new template for SNMP Printer to be available during install
  • feature #5418: When importing devices, allow a device classification to be known
  • feature #5442: Extend length o...
Read more

v1.2.24

27 Feb 14:49
Compare
Choose a tag to compare

Release of Cacti 1.2.24

Thank you everyone who are using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

Please note, that in the previous release, we added extra security around the
use of http headers for remote agent calls. This release now enforces that
change to require admins to set which headers are allowed from a predefined
set and no longer assumes that all of them should be checked.

See $proxy_headers in the config.php.dist include file for more
information. These must b set in the include/config.php if they are
required.

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests!

Cacti Change Log

  • issue #5127: Unable to import Local Linux Machine template
  • issue #5134: Maximum Memory shows -1 instead of Unlimited
  • issue #5135: RRDcleaner and RRDcheck share the same filter details causing errors
  • issue #5136: When passed a null value, number_format_i18n() can return a invalid number by ddb4github
  • issue #5137: When attempting to update structured paths, SQL errors can occur
  • issue #5140: Compatibility changes for SNMP under PHP 8.2
  • issue #5142: Fix issues with permission model and warnings
  • issue #5143: When a Device has zero Graphs or Data Sources, it does not display a value
  • issue #5145: Changing SNMP settings to None leaves Bulk Walk Maximum Repititions visible
  • issue #5147: Language handlers may not always be loaded properly
  • issue #5150: Wrong parameters are shown for the Import Package script
  • issue #5151: Templates appear to lose their suggested name values
  • issue #5159: When editing a tree, the tree can not be set to published
  • issue #5160: Translations on debian 'bookworm' systems may cause server errors
  • issue #5161: Switching language in the settings does not immediately become active
  • issue #5166: Plugin permissions may sometimes appear in the wrong section by ddb4github
  • issue #5167: Graph template for NetSNMP lmsensors missing
  • issue #5168: Import Package is misleading when reviewing Device Template Changes
  • issue #5169: Device failure and recovery dates can be misleading
  • issue #5170: Prevent remote polling functionality from running on main poller
  • issue #5174: When adding a new device, location is not being saved
  • issue #5180: Audit Database has issues with storage engine compare
  • issue #5181: When working with remote data collectors, some errors may be logged
  • issue #5182: Graph Image does not have check for Remote Agent
  • issue #5184: When a user has been deleted, checking permissions can cause errors
  • issue #5185: Repair Database does not prune old Poller Item Records
  • issue #5187: When calling plugin functions, errors can appear if they are not present
  • issue #5188: When filtering Device Templates, valid matches are not always shown
  • issue #5190: When using Gradient Support GPRINT Text Format is misaligned
  • issue #5194: CSRF directory needs to be writeable for creating the csrf-secret.php file
  • issue #5195: When removing spikes, errors can be recorded for NaN samples
  • issue #5196: Gradient support can break Graphs containing special characters
  • issue #5197: Unable to obtain realtime graph from remote poller
  • issue #5198: Compability Improvements for PHP Diff under PHP 8.x
  • issue #5199: When trying to obtain data, cacti should not long Transport Read errors
  • issue #5200: Compatibility improvements for Classic Tab images under PHP 8.x
  • issue #5201: Weathermaps can have issues rendering with some themes
  • issue #5202: When importing packages, Graph Size does not get updated to Graph Templates
  • issue #5203: Host Mib Device package can cause errors with NetSNMP scripts
  • issue #5204: Compatibility improvements for Audit Database under PHP 8.x
  • issue #5205: When using Diff Viewer, rendering is not always correct under certain themes
  • issue #5207: Compatibility improvements for Installer under PHP 8.x
  • issue #5208: Some i18n strings are not properly translated
  • issue #5209: When disabling a user, no log is recorded by xmacan
  • issue #5211: When creating a new graph, undefined variable errors may be recorded
  • issue #5214: Basic Auth is timing out and logging users off automatically
  • issue #5223: When using callback form functions, name and id field may not be correctly set
  • issue #5224: When poller runtime is exceeded, time should be display as a rounded number
  • issue #5227: When debugging a data source, errors may be shown if no RRDfile created yet
  • issue #5232: Polling can appear delayed due to early statistics gathering
  • issue #5236: When viewing a graph, Edit Graph Template link may open wrong url
  • issue #5238: Searching for Poller Items can generates SQL Errors
  • issue #5239: Bulk Walk Maximum Repetitions may sometimes be ignored
  • issue #5241: Balance Process Load does not always apply properly
  • issue #5243: Template Export missing Graph Template columns multiple and test_source
  • issue #5245: Add additional security to the unserialize function by TheWitness
  • issue #5247: Rebuilding Poller Cache from Utilities does not respect poller interval due to lack or ordering

Reporting Issues

http://www.cacti.net/issues.php

Download Cacti

http://www.cacti.net/download_cacti.php

Download Spine

http://www.cacti.net/spine_download.php

Thanks!
The Cacti Group

v1.2.23

02 Jan 15:24
Compare
Choose a tag to compare

Release of Cacti 1.2.23

Thank you to everyone who is using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

IMPORTANT: A security issue was identified that could allow remote attackers to bypass IP restrictions to the remote agent service when proxy headers are defined.

Starting with 1.2.23, it is the admins responsibility to define which proxy headers are valid. However, to ensure that access to systems are not lost, until these are explicitly configured, the full list of proxy headers will be allowed and a warning will be displayed in the system logs daily.

If you see this warning, please set the desired headers or false within include/config.php immediately

In the 1.3.0 (development) version, no headers are configured and must be manually set. If you are using a proxy server, ensure these are configured within include/config.php

For more information, refer to issue security#5119

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork, and pull requests!

Cacti Change Log

  • security #4920: Add .htaccess file to scripts folder
  • security #5119: CVE-2022-46169 Unauthenticated Command Injection in Remote Agent
  • issue #4418: When using Single Sign-on Frameworks, revocation is not always detected in callbacks
  • issue #4682: New templates are not installed during the update
  • issue #4738: Improve PHP 8.1 support for Installer CLI
  • issue #4888: The database audit script fails to run properly on MySQL 8.0.29
  • issue #4889: Increase host query performance by removing check for NULL
  • issue #4892: When many hosts go offline, Recache Event can be constantly logged
  • issue #4893: Real Time Counter can become stuck and does not count down
  • issue #4896: When remote poller is in offline mode, GUI can become inaccesible and poller can timeout
  • issue #4897: Technical support page on remote poller shows max connections of Main poller
  • issue #4903: Correct incompatibility between MySQL 8.x and Automation regular expressions
  • issue #4904: The recommendation for innodb_buffer_pool_instances is incorrect for MySQL 8 and MariaDB < 10.5
  • issue #4905: Using colons in labels can break graphs with gradients
  • issue #4917: Real Time Counter can become stuck and does not count down
  • issue #4921: Some Aggregate graphs can be denied access incorrectly
  • issue #4923: Unable to duplicate a Graph template
  • issue #4927: Unable to audit the database if database password contains a bracket
  • issue #4934: Upgrade phpseclib to 2.0.37
  • issue #4935: The 'Net-SNMP - Device I/O' template incorrectly sets a maximum value of zero
  • issue #4940: When sorting by hostname, database errors can be reported
  • issue #4941: When boost is running, graphs can appear broken
  • issue #4944: Packages should be signed with SHA256 as SHA1 is considered deprecated
  • issue #4947: When creating a Data Template, ensure that the default max value is always 'U' and not '0'
  • issue #4951: Plugins may not work correctly with Multi-Poller setups
  • issue #4960: Setting context for connections throws error in PHP 8.x
  • issue #4963: Wen calculating 95th percentile, floor() maybe used instead of ceil() incorrectly
  • issue #4964: Tree search does not correct hide non-matching tree objects
  • issue #4966: Device Template filters should show on used templates
  • issue #4971: MIB Parser can sometimes cause errors in later PHP versions
  • issue #4978: Boost may sometimes lose the Time Zone unexpectedly
  • issue #4980: Setting business hours can cause PHP errors
  • issue #4988: When creating RRD File, more data sources than expected may be defined
  • issue #4990: When viewing Links, errors can be generated
  • issue #4991: Updating a Data Template does not switch rrd_heartbeat properly for all sources leading to empty graphs
  • issue #4993: Data Debug Troubleshooter does not pick up invalid RRD_heartbeat settings
  • issue #4996: When managing graphs, Graphs can be listed multiple times incorrectly
  • issue #5001: Data Debug troubleshooter reports false positives with Missing Data Sources
  • issue #5006: Errors can occur when attempting to remove items from CDEF or VDEF's
  • issue #5012: When upgrading database at command line, some PHP errors may be seen
  • issue #5013: Automatically set Bulk Walk size when missing on a host
  • issue #5015: Upgrade for 1.2.21 reporting unknown status
  • issue #5017: SNMP Agent can cause unexpected errors due to implicit rounding
  • issue #5018: When using 'Remember me', session can still be forced to end unexpectedly
  • issue #5024: Escape char not properly replaced in snmp strings
  • issue #5028: Cacti User Stats script can throw errors unexpectedly
  • issue #5029: Searching for a plugin by name does not always work
  • issue #5030: Installer shows innodb unset in MariaDB 10.10+
  • issue #5033: Improve PHP 8.1 support with Installer
  • issue #5034: RRD Proxy Server not supported by CLI script "structure_rra_paths.php"
  • issue #5041: Custom themes may cause errors if they do not contain all required CSS/JS files
  • issue #5057: When adding a device rule in automation, depreciated filters may be reported
  • issue #5066: Graph watermark is not escaped properly, leading to broken graphs
  • issue #5068: Improve PHP 8.2 support with Installer
  • issue #5084: When viewing trees, runtime errors may be recorded
  • issue #5088: When running script host_update_template.php, reindex method may incorrectly be changed to uptime
  • issue #5089: When numeric regex validation fails, no backtrace is logged
  • issue #5096: When the SNMP Agent is enabled, certain objects can result in errors appearing
  • issue #5097: RRDtool Utilities should not appear on Remote Data Collectors
  • issue #5101: When a remote poller fails, the recovery process may also fail
  • issue #5102: When in Recovery Mode, plugins that are designed to work remotely stop working
  • issue #5103: When Remote Data Collector changes status, a full page refresh or logout should occur
  • issue #5105: ss_host_disk.php php issue after upgrade PHP 8.1 (from 7.4)
  • issue #5107: Block installation if PHP has session.auto_start enabled
  • issue #5111: During boost processing, some DS Stats functions can cause errors
  • feature #1100: Structured path not created when using remote poller and Update On-Demand
  • feature #1392: Notify Admins that page errors exist even when using dynamic callbacks
  • feature #2239: Allow Import and Export to be more selective
  • feature #2485: Importing Template requires you to upload the same file after previewing
  • feature #2548: Add Head/Tail filtering of log for more efficient searches
  • feature #2567: The innodb sort buffer should be optimized for large tables
  • feature #2747: Allow more sorting options when managing Graphs
  • feature #2871: Report when RRA's heartbeat is below the data source profile's interval
  • feature #3131: Add utility feature to reindex hosts with bad indexes
  • feature #3578: Allow Re-indexing of Devices to be Scheduled
  • feature #4025: When importing a Template or Package, allow the user to ignore template and use the system default dimensions
  • feature #4239: On "Graph Utility View" add the name of and a link to the graph template which the graph is based on
  • feature #4417: Support execution of custom functions at poller bottom for remote pollers
  • feature #4754: The script ss_fping.php should timeout based on the host
  • feature #4762: Allow Package Import to be selective
  • feature #4786: Windows install does not support SVG rendering
  • feature #4820: When importing, make it possible to only import certain components
  • feature #4841: Move the cactid function db_check_reconnect() to lib/database.php for other service oriented scripts
  • feature #4874: Add support for Business Hours
  • feature #4890: Add multi threading for Poller recache script
  • feature #4899: Allow script server to be told when the main database when offline or in recovery
  • feature #4901: Make the script server accept arguments in the standard way
  • feature #4902: Increase compatibility with MySQL 8.x
  • feature #4907: Add lmSensors to the Net-SNMP Device Template
  • feature #4926: Allow the user to override Cacti's built-in Time Zone detection
  • feature #4943: Add ability to periodically check RRDfiles for errors in batch
  • feature #4948: When security cookie times out, redirection does not always occur properly
  • feature #4955: Provide memory tuning based upon MySQL Tuner recommendations
  • feature #4956: The function db_check_reconnect() should be able to work with any connection
  • feature #4957: Add Device Template categories to match the classes of the Package Plugin
  • feature #4965: When unlocking a tree, entire page should not need rebuilding
  • feature #4967: Make adding Associated Graph Templates and Data Queries easier to use
  • feature #4989: Improve table performance by caching 'Total Rows' using a hash
  • feature #5009: Allow SNMP Value OIDs to be parsed using regular expressions
  • feature: Adding ESXi Device Template
  • feature: Upgrade jQuery to version 3.6.1
  • feature: Upgrade jQueryUI to version 1.13.2
  • feature: Upgrade billboard.js to version 3.6
  • feature: Introduce exec() function with timeout

Reporting Issues

http://www.cacti.net/issues.php

Download Cacti

http://www.cacti.net/download_cacti.php

Download Spine

http://www.cacti.net/spine_download.php

Thanks!
The Cacti Group

What's Changed

  • Added support for showing business hours by @thurban in #4878
  • Labels on AREA having a colon breaks the gradient creation with an rrdtool error by @thurban in #4900
  • Fix cisco router template BGP by @bmfma...
Read more

v1.2.22

14 Aug 22:01
Compare
Choose a tag to compare

Release of Cacti 1.2.22

Thank you everyone who are using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests!

Cacti Change Log

  • security #4834: When creating new graphs, cross site injection is possible
  • issue #4768: When creating user from template, multiple Domain FullName and Mail are not propagated
  • issue #4791: Nectar Aggregate 95th emailed report broken
  • issue #4796: Boost may not find archive tables correctly
  • issue #4802: Users may be unable to change their password when forced during a login
  • issue #4803: Net-SNMP Memory Graph Template has Wrong GPRINT
  • issue #4806: Search in tree view unusable on larger installations
  • issue #4808: Increased bulk insert size to avoid partial inserts and potential data loss.
  • issue #4810: Call to undefined function boost_debug in Cacti log
  • issue #4814: When no guest template is set, login cookies are not properly set
  • issue #4817: Later RRDtool releases do not need to check last_update time
  • issue #4818: Regex filters are not always long enough
  • issue #4819: Domains based LDAP and AD Fullname and Email not auto-populated
  • issue #4822: Cacti polling and boost report the wrong number of Data Sources when Devices are disabled
  • issue #4823: When editing Graph Template Items there are cases where VDEF's are hidden when they should be shown
  • issue #4831: Database SSL setting lacks default value
  • issue #4837: Update default path cacti under *BSD by xmacan
  • issue #4840: Web Basic authentication not creating template user
  • issue #4846: Unable to change the Heartbeat of a Data Source Profile
  • issue #4849: Tree Search Does Not Properly Search All Trees
  • issue #4850: When structured paths are setup, RRDfiles may not always be created when possible
  • issue #4851: When parsing the logs, caching would help speed up processing
  • issue #4853: Deprecation warnings when attempting real-time Graphs with PHP8.1
  • issue #4860: Custom Timespan is lost when clicking other tree branches
  • issue #4863: Non device based Data Sources not being polled
  • issue #4865: When Resource XML file inproperly formatted, graph creation can fail with errors
  • issue #4866: Update code style to support PHP 8 requirements
  • issue #4867: In Graph Management, filtering for "Device: None" shows all graphs
  • issue #4871: Realtime popup window experiences issues on some browsers
  • issue #4873: Auth settings do not always properly reflect the options selected by ddb4github
  • issue #4880: MySQL can cause cacti to become stalled due to locking issues
  • issue #4882: Boost process can get hung under rare conditions until the poller times out
  • issue #4884: Exporting graphs under PHP 8 can cause errors
  • issue #4887: Host table has wrong default for disabled and deleted columns
  • feature #4533: RRD storage paths do not scale properly
  • feature #4820: When importing, make it possible to only import certain components
  • feature #4825: Update change_device script to include new features by bmfmancini
  • feature #4827: Make help pages use latest online version wherever possible
  • feature #4832: Cacti should show PHP INI locations during install
  • feature #4833: Detect PHP INI values that are different in the INI vs running config
  • feature #4870: Added Gradient Color support for AREA charts by thurban
  • feature #4872: Update CDEF functions for RRDtool
  • feature #4881: When boost is running, it's not clear which processes are running and how long they have to complete

Reporting Issues

http://www.cacti.net/issues.php

Download Cacti

http://www.cacti.net/download_cacti.php

Download Spine

http://www.cacti.net/spine_download.php

Thanks!
The Cacti Group

v1.2.21

18 May 23:21
Compare
Choose a tag to compare

Release of Cacti 1.2.21

Thank you everyone who are using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests!

Cacti Change Log

  • issue #4531: Correct duplicate keys within database
  • issue #4614: Add support for hooks during polling loop or at poller end
  • issue #4683: When adding a device, errors may be reported whilst updating templates
  • issue #4684: When creating RRD error image, font may not exist by xmacan
  • issue #4685: Correct issues with corrupted Cacti Packages
  • issue #4687: Poller output not empty all the time
  • issue #4688: When running under PHP 5.4, certain operators are not valid by ddb4github
  • issue #4689: Package Import generates errors when you try to import directory or non-file
  • issue #4693: Correct issues with Heartbeat definitions under PHP 8.x
  • issue #4695: When importing packages, hash types are not properly processed by ddb4github
  • issue #4697: Login problem
  • issue #4698: When creating a device, unexpected poller down message may be shown
  • issue #4701: Editing a new user or user group may cause errors
  • issue #4705: Unable to automatically login using Remember Me option
  • issue #4707: Unable to duplicate graph templates due to missing column
  • issue #4716: Correct issues with Data Source Edit under PHP 8.x
  • issue #4719: Browsers may reject CactiTimeZone and CactiDateTime cookies due to SameSite requirements
  • issue #4721: Some JavaScript and image files URL are broken under midwinter theme by ddb4github
  • issue #4722: When upgrading from pre 1.x, various errors may be seen by ddb4github
  • issue #4726: When running under Fedora, issues may be seen with snmp values
  • issue #4729: Add ability for Template and Package Installs to update Suggested Name Values/Patterns
  • issue #4732: When using audit tool, text/mediumtext columns may not be properly processed by ddb4github
  • issue #4735: When changing data source profiles, errors may be shown
  • issue #4736: Update PHP recommendations to meet current expectations
  • issue #4743: When viewing graphs, fontawesome may not always been found
  • issue #4744: When using automation, numeric values may be treated as strings
  • issue #4748: When saving a device, errors may be generated
  • issue #4756: Importing very old Data Input Methods generate dependency warnings
  • issue #4757: Correct issues with Boost running under PHP 8.x
  • issue #4763: Unable to login locally when LDAP authentication enabled
  • feature #4720: Add a CLI script to install/enable/disable/uninstall plugins
  • feature #4740: Add log message when purging DS stats and poller repopulate

Reporting Issues

http://www.cacti.net/issues.php

Download Cacti

http://www.cacti.net/download_cacti.php

Download Spine

http://www.cacti.net/spine_download.php

Thanks!
The Cacti Group

v1.2.20

06 Apr 13:28
Compare
Choose a tag to compare

Release of Cacti 1.2.20

Thank you everyone who are using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

Some notable changes that appear in this release are:

  • Authentication now provides support for external auth services
  • Performance improvements with Graph Templates, Reports and Permissions
  • Additional device templates supplied for import during install/upgrade
  • Improved remote Data Collector handling

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests!

Cacti Change Log

  • security #4562: When using LDAP, authentication process may be bypassed
  • security #4576: Device, Graph, Graph Template, and Graph Items may be vulnerable to XSS issues
  • security #4579: Lockout policies are not properly applied to LDAP and Domain Users
  • security #4593: When using 'remember me' option, incorrect realm may be selected
  • security #4678: User and Group maintenance are vulnerable to SQL attacks
  • security #4679: Color Templates are vulnerable to XSS attack
  • issue #3816: When replicating data during installation/upgrade, system may appear to hang
  • issue #4363: Graph Template Items may have duplicated entries
  • issue #4435: Unable to Save Graph Settings
  • issue #4449: Script Server may crash if an OID is missing or unavailable
  • issue #4451: When system-wide polling is disabled, remote pollers may fail to sync changed settings
  • issue #4455: When updating poller name, duplicate name protection may be over zealous
  • issue #4457: Titles may show "Missing Datasource" incorectly
  • issue #4458: Checking for MIB Cache can cause crashes
  • issue #4460: Polling cycles may not always complete as expected
  • issue #4461: When viewing graph data, non-numeric values may appear
  • issue #4472: Utilities view has calculation errors when there are no data sources
  • issue #4475: Add support for PHP 8
  • issue #4477: Remote pollers do not force connection when online
  • issue #4479: Rebuild Poller Cache CLI script should have filter options
  • issue #4480: Saving a bad Data Template can damage Data Sources
  • issue #4481: Reports still use Legacy attributes, despite having a format file
  • issue #4482: Graph Automation slowed by in-efficient index selection
  • issue #4491: When rebuilding poller cache, SNMP settings do not properly update
  • issue #4492: When an OID starts with space, SNMP returns undefined data
  • issue #4495: Datasource Statistics may obtain invalid data for some rebooted devices
  • issue #4498: When attempting to calculate width, some input elements may cause console errors
  • issue #4500: Datasource Statistics may not scale properly on larger systems
  • issue #4508: Changing Multi-Device SNMP settings may not work as expected
  • issue #4509: Updating Items for a Graph Template may be slow on larger systems
  • issue #4511: When using the time-based view, SVG Graphs may not resize properly
  • issue #4512: When using API calls, graphs without data sources may be unremovable
  • issue #4516: Add additional information to help when creating graphs from templates
  • issue #4519: When remote host poll fails, poller ID may not be found and cause errors
  • issue #4521: Backtraces Logged in Cacti 1.2.x Branch - Gettext Translation
  • issue #4522: When entering custom input, layout issues may be seen
  • issue #4528: When creating a device, default setting for Device Threads may be ignored
  • issue #4529: Primary Admin account notifications may not work in certain cases
  • issue #4530: On larger systems, user interface for reporting may become unusable
  • issue #4536: When using Web Basic Authentication, user is always mapped as guest.
  • issue #4539: When handling plugin dependancies, notices may not be displayed properly
  • issue #4540: Certain account types should not allow their enabled status to be changed
  • issue #4543: Emails sent multiple times to the same address can be rejected
  • issue #4545: Reports Tab always shows 'Administration' despite a users permissions
  • issue #4546: When unauthorized, user may be redirected instead of notified
  • issue #4547: Add debug options to LDAP for diagnostic purposes
  • issue #4548: Rounding causes errors with variable substitution
  • issue #4549: Boost may become disabled due to an invalid path
  • issue #4551: Add support for PHP 8
  • issue #4552: Error messages are not always cleared, resulting in duplicated messages.
  • issue #4554: Add support for Automation under PHP 8
  • issue #4557: When selecting a Consolidation Function, errors may be reported
  • issue #4563: Breadcrumbs not always display the correct path
  • issue #4564: When clicking tabs, page may not always respond
  • issue #4567: Editing current user should prevent changes of account status
  • issue #4568: Authentication cache does not always use the correct realm
  • issue #4569: When editing users or groups, template permissions may not work as intended
  • issue #4571: When changing authentication method, unneeded settings may not be hidden
  • issue #4572: When basic authentication is used, login screen should not be seen
  • issue #4573: On larger systems, permission checks may render system unusable
  • issue #4575: When you delete a user, cookie data is not automatically removed
  • issue #4577: When editing current user, last administrator may be removed
  • issue #4578: The Cacti login algorithm is complicated to understand due to too much strait line code
  • issue #4580: When using Web Basic Authentication, users may be seen as guests
  • issue #4586: When viewing graphs, excess database queries may occur
  • issue #4587: Settings may be read more often than required
  • issue #4588: Unable to save host with multi-byte characters
  • issue #4589: When updating tables, ensure engine, row_format and charset by ddb4github
  • issue #4594: When selecting font, attempt to use system-based font before internally supplied version by ddb4github
  • issue #4597: Selective Device Debug does not work with Remote Data Collectors
  • issue #4598: Plugin tab does not stay visible when main poller is offline
  • issue #4603: When failing back to PHP GetText, module is not always selected
  • issue #4607: Configuration file may be improperly moved into the resource cache
  • issue #4609: When handling sessions, user agent may not always be present
  • issue #4610: When hiding disabled devices, some may still be shown
  • issue #4611: When replicating to remote pollers, plugins are not always properly sync'd
  • issue #4612: When using cookie authentication, Same Site support does not always work properly
  • issue #4613: Newer versions of MySQL/MariaDB may prevent structure replication changes
  • issue #4614: Add support for hooks during polling loop or at poller end
  • issue #4615: Plugin status on a Remote Data Collector may not always be detectable
  • issue #4616: When performing certain plugin actions, replication should be forced to Remote Collectors
  • issue #4617: When removing a plugin, removed tables are not removed from remote pollers
  • issue #4618: When plugin exceed runtimes, they should not be automatic disabled
  • issue #4620: When using CLI, Remote Data Collector scripts may connect to the wrong database
  • issue #4623: Boost does not operate as it should in certain situations
  • issue #4624: System uptime may be missing under certain circumstances
  • issue #4629: When removing many Graphs and Data Sources, polling cycles may overrun
  • issue #4630: Session data is not always started correctly
  • issue #4632: When creating a Datasource, Input Field Checking is not always enforced
  • issue #4634: When using Basic Authentication, the Logout Everywhere button should not be shown
  • issue #4645: When format file does not exist, changing certain settings may result in errors
  • issue #4651: Device Description is not consistent in Poller Cache view
  • issue #4652: After repopulating graph, navigation to check cumbersome
  • issue #4654: When saving a data template, replication may cause errors
  • issue #4658: When upgrading from pre-1.0, tree information may not properly update by ddb4github
  • issue #4659: When moving a device between pollers, errors may occur
  • issue #4666: Add date calculation support for PHP 8
  • issue #4671: Add poller sleeping support for PHP 8
  • issue #4672: When editing Reports, drag and drop may not function as intended
  • issue #4680: When data drive is full, viewing a Graph can result in errors
  • feature #4574: On larger systems, permissions may need alternative methods
  • feature #4631: When creating a Data Source Profile, allow additional choices for Heartbeat
  • feature #4636: Upgrade jQueryMulti-select to 3.0.1
  • feature #4637: Change select all options to use Font Awesome icons
  • feature #4641: Improve spine performance by storing the total number of system snmp_ports in use
  • feature #4663: Prevent Template User Accounts from being Removed
  • feature #4664: When managing by users, allow filtering by Realm
  • feature #4665: Allow plugins to supply template account names
  • feature #4667: When viewing logs, additional message types should be filterable
  • feature #4668: When creating a Graph Template Item, allow filtering by Data Template
  • feature #4669: Allow language handler to be selected via UI
  • feature #4673: Updated Device packages for Synology, Citrix NetScaler, Cisco ASA/Cisco
  • feature #4674: Add Advanced Ping Graph Template to initial Installable templates
  • feature #4675: Add LDAP Debug Mode option
  • feature #4676: Allow Reports to include devices not on a Tree
  • feature #4677: Allow Basic Authentication to display custom failure message

Reporting Issues

http://www.cacti.net/issues.php

Download Cacti

http://www.cacti.net/download_cacti.php

...

Read more

v1.2.19

29 Oct 18:35
Compare
Choose a tag to compare

Release of Cacti 1.2.19

Thank you everyone who are using Cacti and especially those helping to make Cacti better!

For additional details check out the README located on GitHub.

Contribute

Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests!

Cacti Change Log

  • security #4356: Further fixes for grave character security protection
  • issue: Over aggressive escaping causes menu visibility issues on Create Device page
  • issue #3787: Add SHA256 and AES256 security levels for SNMP polling
  • issue #4289: Import graph template(Preview Only) show color_id new value as a blank area
  • issue #4341: Editing graphs can cause errors due to missing sequence
  • issue #4342: When hovering over a Tree Graph, row shows same highlighting as Graph Edit screen
  • issue #4343: When RealTime is not active, console errors may appear
  • issue #4347: Race conditions may occur when multiple RRDtool processes are running
  • issue #4352: Creating graphs from templates may sometimes result in errors
  • issue #4353: When duplicating reports, errors may occur
  • issue #4375: Boost may be blocked by overflowing poller_output table
  • issue #4378: Template import may be blocked due to unmet dependency warnings with snmp ports
  • issue #4381: Newer MySQL versions may error if committing a transaction when not in one
  • issue #4382: SNMP Agent may not find a cache item
  • issue #4383: Correct issues running under PHP 8.x
  • issue #4391: When polling is disabled, boost may crash and creates many arch tables
  • issue #4396: When poller runs, memory tables may not always be present
  • issue #4400: Removal of redunant code
  • issue #4403: Timezones may sometimes be incorrectly calculated
  • issue #4404: Allow monitoring IPv6 with interface graphs
  • issue #4408: When a data source uses a Data Input Method, those without a mapping should be flagged
  • issue #4410: When RRDfile is not yet created, errors may appear when displaying the graph
  • issue #4419: Cacti missing key indexes that result in Preset pages slowdowns
  • issue #4420: Data Sources page shows no name when Data Source has no name cache
  • issue #4421: db_update_table function can not alter table from signed to unsigned
  • issue #4422: data remains in poller_output table even if it's flushed to rrd files
  • issue #4423: Parameter list for lib/database.php:db_connect_real() is not correct in 3 places
  • issue #4424: Offset is a reserved word in MariaDB 10.6 affecting Report
  • issue #4425: Rendering large trees slowed due to lack of permission caching
  • issue #4428: Error on interpretation of snmpUtime, when to big
  • issue #4431: Applying right axis formatting creates an error-image
  • issue #4435: Unable to Save Graph Settings from the Graphs pages
  • issue #4437: Graph Template Cache is nullified too often when Graph Automation is running
  • issue #4438: When Adding a Data Query to a Device, no Progress Spinner is shown
  • issue #4439: New Browser Breaks Plugins that depend on non UTC date time data
  • issue #4440: Undefined index: timeout_exceed /lib/poller.php on line: 1953
  • issue #4442: When testing remote poller connectivity Errors occour
  • issue #4443: When renaming poller errors occour
  • issue #4444: Removing spikes by Variance does not appear to be working beyond the first RRA
  • issue #4445: LDAP API lacks timeout options leading to bad login experiences
  • feature: Add a normal/wrap class for general use
  • feature: Limit File Types available for Template Import operations
  • feature #1573: Cacti does not provide an option of providing a client side certificate for LDAP/AD authentication
  • feature #3113: Support Stronger Encryption Available Starting in Net-SNMP v5.8
  • feature #4299: Allow Cacti to use multiple possible LDAP servers
  • feature #4344: Add a 15 minute polling/sampling interval
  • feature #4385: Provide additional admin email notifications
  • feature #4390: Add warnings for undesired changes to plugin hook return values
  • feature #4409: When creating a Graph, make testing the Data Sources optional by Template
  • feature #4412: Update phpseclib to 2.0.33
  • feature #4413: Update jstree.js to 3.3.12
  • feature #4414: Improve performance of Cacti poller on heavily loaded systems
  • feature #4426: MariaDB recommendations need some tuning for recent updates

Reporting Issues

http://www.cacti.net/issues.php

Download Cacti

http://www.cacti.net/download_cacti.php

Download Spine

http://www.cacti.net/spine_download.php

Thanks!
The Cacti Group