Released: March 2020
What's new?
There is a new API endpoint that allows you to manage the policy setting (allowed/blocked) for a set of categories.
Support has been added to signal to Firefox that DNS filtering is being used. See support.mozilla.org
Usage reports can now be generated by group.
What has been improved?
Security patches for packages, including OpenSSL (CVE-2019-1551), PHP and Sudo (CVE-2019-18634).
API no longer reports on bypassed traffic. These are included in the allowed traffic.
The API maximum limit for top stats has increased from 100 to 1000.
API history endpoint now includes location and effective policy details.
There are increased password complexity requirements for new passwords. Passwords must now be 10 characters long and contain a letter, number or symbol.
We have disabled support for SSLv3, TLS1.0 and disabled weak ciphers.
Patches and hotfixes can now be retrieved using HTTPS only.
What has been fixed?
Internal IP address displaying on the block page.
Resolved issue responding to certain requests when the truncated bit is enabled, by switching to TCP.
A potential vulnerability when restoring a backup file.
The customer timezone not being taken into account in notification emails or scheduled reports.
Additional cookie security attributes are now applied to prevent session stealing.
A potential session fixation security issue has been resolved by removing the FLASH_PHPSESSID setting.
A potential SQL injection vulnerability has been resolved.
Problem filtering history by customer when using an account that was deleted and then re-created.
Issue when attempting to import allow and block list entries before saving a new policy.