I’ve rolled out Webmin version 1.990 to all repos.
- Fixed two security bugs in the File Manager module that could be exploited by less privileged Webmin users.
- Added buttons to stop and start the Cron daemon.
- Fail2ban rules are preserved when applying the IPtables configuration file.
- Added support for static routes when using Netplan for network configuration.
- Updated Authentic Theme to the latest version.
- Updated the UI in several modules to use the latest API and be more consistent with the rest of Webmin.
The File Manager security bugs won’t impact most Virtualmin users, as Virtualmin domain owners have more tightly restricted File Manager permissions by default. But, you should update ASAP, anyway.
Thanks to Faisal Fs (faisalfs10x) from NetbyteSEC for discovering and responsibly disclosing the two File Manager issues.
As always, let us know if you run into any problems (please start a new topic with any questions or problems).
After the update, Usermin throws the following error:
HTTP/1.0 500 Perl execution failed Server: MiniServ/1.834 Date: Sat, 5 Mar 2022 09:12:13 GMT Content-type: text/html; Charset=utf-8 Connection: close
ERROR — PERL EXECUTION FAILED
Undefined subroutine &WebminCore::getvar called at /usr/share/usermin/authentic-theme/authentic.pl line 59.
Thanks for the hard work!
I notice this issue some time ago: In Firefox 97 after login, the right zone " System Information" keep loading, I can see the little red bar in the top only and the grey screen (the background) I need to reload page or click again in the Webmin icon in the top left for load the data.
Tested in latest Chrome no issues at all.
My client PC: Ubuntu 21.10
Me too on 2 installs, worked on 3 others
I re-ran the update from the command line and after an hour it completed. Other machines with the same 1.984 to 1.990 update took 2 minutes.
We don’t have any control over the speed of your network (I assume that’s why it was slow…though the package is only 39M).
Ya’ll, please open new topics about any problems you have!