{"id":369728,"date":"2024-04-17T16:12:32","date_gmt":"2024-04-17T16:12:32","guid":{"rendered":"https:\/\/pandorafms.com\/?p=369728"},"modified":"2025-07-03T20:38:34","modified_gmt":"2025-07-03T20:38:34","slug":"772-4-lts","status":"publish","type":"post","link":"https:\/\/pandorafms.com\/es\/notas-de-parches\/772-4-lts\/","title":{"rendered":"772.4 LTS"},"content":{"rendered":"<p>[et_pb_section fb_built=\u00bb1&#8243; _builder_version=\u00bb4.22.0&#8243; _module_preset=\u00bbdefault\u00bb custom_margin=\u00bb0px||||false|false\u00bb custom_padding=\u00bb0px||||false|false\u00bb global_colors_info=\u00bb{}\u00bb][et_pb_row _builder_version=\u00bb4.22.0&#8243; _module_preset=\u00bbdefault\u00bb z_index=\u00bb0&#8243; width=\u00bb100%\u00bb max_width=\u00bb900px\u00bb module_alignment=\u00bbleft\u00bb custom_margin=\u00bb0px||0px||true|false\u00bb custom_padding=\u00bb0px||0px||true|false\u00bb global_colors_info=\u00bb{}\u00bb][et_pb_column type=\u00bb4_4&#8243; _builder_version=\u00bb4.21.0&#8243; _module_preset=\u00bbdefault\u00bb global_colors_info=\u00bb{}\u00bb][et_pb_text module_id=\u00bb1&#8243; _builder_version=\u00bb4.22.0&#8243; _module_preset=\u00bbdefault\u00bb z_index=\u00bb0&#8243; custom_margin=\u00bb0px||0px||true|false\u00bb custom_padding=\u00bb0px||0px||true|false\u00bb custom_css_main_element=\u00bbfont-family:%22Pandora-Light%22;\u00bb locked=\u00bboff\u00bb global_colors_info=\u00bb{}\u00bb]<\/p>\n<h2>Parches LTS<\/h2>\n<p>Publicamos parches exclusivamente para las versiones de Soporte Extendido (LTS), a menos que haya situaciones espec\u00edficas en las que tambi\u00e9n lanzamos parches para las versiones de Lanzamiento Regular (RRR).<\/p>\n<p>Los parches de seguridad se publican lo antes posible, tras detectar y corregir la vulnerabilidad. Los parches para la versi\u00f3n LTS incluyen principalmente correcci\u00f3n de fallos cr\u00edticos y soluciones a problemas de seguridad.<\/p>\n<p>[\/et_pb_text][et_pb_divider color=\u00bb#eaeaea\u00bb divider_position=\u00bbcenter\u00bb divider_weight=\u00bb1px\u00bb admin_label=\u00bb=== SEPARADOR ===\u00bb module_id=\u00bb2&#8243; _builder_version=\u00bb4.22.0&#8243; _module_preset=\u00bbdefault\u00bb z_index=\u00bb0&#8243; module_alignment=\u00bbcenter\u00bb custom_margin=\u00bb0px||0px||true|false\u00bb custom_padding=\u00bb25px||25px||true|false\u00bb border_color_all=\u00bb#eaeaea\u00bb locked=\u00bboff\u00bb global_colors_info=\u00bb{}\u00bb][\/et_pb_divider][et_pb_code admin_label=\u00bbFallos corregidos\u00bb _builder_version=\u00bb4.22.0&#8243; _module_preset=\u00bbdefault\u00bb z_index=\u00bb0&#8243; custom_margin=\u00bb0px||0px||true|false\u00bb custom_padding=\u00bb0px||0px||true|false\u00bb hover_enabled=\u00bb0&#8243; locked=\u00bboff\u00bb global_colors_info=\u00bb{}\u00bb sticky_enabled=\u00bb0&#8243;]<\/p>\n<h2>Fallos corregidos<\/h2>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<table class=\"PandoTable6\" style=\"margin-top: 30px;\"><!-- [et_pb_line_break_holder] --><\/p>\n<thead><!-- [et_pb_line_break_holder] --><\/p>\n<tr><!-- [et_pb_line_break_holder] --><\/p>\n<th>Caso#<\/th>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<th>GitLab#<\/th>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<th>Descripci\u00f3n<\/th>\n<p><!-- [et_pb_line_break_holder] --><\/tr>\n<p><!-- [et_pb_line_break_holder] --><\/thead>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<tbody><!-- [et_pb_line_break_holder] --><\/p>\n<tr><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>17097<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>12909<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] -->  <pee>Al momento de crear una pol\u00edtica de monitorizaci\u00f3n con m\u00f3dulos de tipo <i>pluginserver<\/i> fue corregido para que todos los campos especificados sean guardados en la base de datos.<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/tr>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<tr><!-- [et_pb_line_break_holder] --><\/p>\n<td>  <!-- [et_pb_line_break_holder] --><pee>16084<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>12401<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>Los problemas con valores negativos en consultas SNMP fueron corregidos.<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/tr>\n<p><!-- [et_pb_line_break_holder] --><\/tbody>\n<p><!-- [et_pb_line_break_holder] --><\/table>\n<p>[\/et_pb_code][et_pb_divider color=\u00bb#eaeaea\u00bb divider_position=\u00bbcenter\u00bb divider_weight=\u00bb1px\u00bb admin_label=\u00bb=== SEPARADOR ===\u00bb module_id=\u00bb2&#8243; _builder_version=\u00bb4.22.0&#8243; _module_preset=\u00bbdefault\u00bb z_index=\u00bb0&#8243; module_alignment=\u00bbcenter\u00bb custom_margin=\u00bb0px||0px||true|false\u00bb custom_padding=\u00bb25px||25px||true|false\u00bb border_color_all=\u00bb#eaeaea\u00bb locked=\u00bboff\u00bb global_colors_info=\u00bb{}\u00bb][\/et_pb_divider][et_pb_code admin_label=\u00bbVulnerabilidades corregidas\u00bb _builder_version=\u00bb4.22.0&#8243; _module_preset=\u00bbdefault\u00bb z_index=\u00bb0&#8243; custom_margin=\u00bb0px||0px||true|false\u00bb custom_padding=\u00bb0px||0px||true|false\u00bb locked=\u00bboff\u00bb global_colors_info=\u00bb{}\u00bb]<\/p>\n<h2>Vulnerabilidades corregidas<\/h2>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<table class=\"PandoTable6\" style=\"margin-top: 30px;\"><!-- [et_pb_line_break_holder] --><\/p>\n<thead><!-- [et_pb_line_break_holder] --><\/p>\n<tr><!-- [et_pb_line_break_holder] --><\/p>\n<th>Caso#<\/th>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<th>GitLab#<\/th>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<th>Descripci\u00f3n<\/th>\n<p><!-- [et_pb_line_break_holder] --><\/tr>\n<p><!-- [et_pb_line_break_holder] --><\/thead>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<tbody><!-- [et_pb_line_break_holder] --><\/p>\n<tr><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-41793\" target=\"_blank\" rel=\"noopener\">CVE-2023-41793<\/a> Agradecimiento a Aleksey Solovev.<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>12751<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>En la subida de recursos para los <i>plugins<\/i> fue corregida y evitada la posibilidad de alojar ficheros fuera del directorio dedicado para ello. Con esta correcci\u00f3n se elude la ejecuci\u00f3n de c\u00f3digo arbitrario en el servidor.<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/tr>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<tr><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-44091\" target=\"_blank\" rel=\"noopener\">CVE-2023-44091<\/a> Agradecimiento a Aleksey Solovev.<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>12752<\/pee><!-- [et_pb_line_break_holder] --><\/p>\n<ul>\n<li>Relacionados: 10902 y 12750<\/li>\n<\/ul>\n<p><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>Ha sido corregida y evitada la posibilidad de un <a href=\"https:\/\/www.sqlinjection.net\/time-based\/\" target=\"_blank\" rel=\"noopener\">ataque de tiempo cronometrado por inyecci\u00f3n de SQL<\/a> en la API 1.0 PFMS.<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/tr>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<tr><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-44090\" target=\"_blank\" rel=\"noopener\">CVE-2023-44090<\/a> Agradecimiento a Aleksey Solovev.<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>12798<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/p>\n<td><!-- [et_pb_line_break_holder] --><pee>En la extensi\u00f3n para conectar a Grafana se ha corregido la posibilidad de inyecci\u00f3n de c\u00f3digo en el SQL correspondiente.<\/pee><!-- [et_pb_line_break_holder] --><\/td>\n<p><!-- [et_pb_line_break_holder] --><\/tr>\n<p><!-- [et_pb_line_break_holder] --><\/tbody>\n<p><!-- [et_pb_line_break_holder] --><\/table>\n<p>[\/et_pb_code][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Parches LTS Publicamos parches exclusivamente para las versiones de Soporte Extendido (LTS), a menos que haya situaciones espec\u00edficas en las que tambi\u00e9n lanzamos parches para las versiones de Lanzamiento Regular (RRR). Los parches de seguridad se publican lo antes posible, tras detectar y corregir la vulnerabilidad. Los parches para la versi\u00f3n LTS incluyen principalmente correcci\u00f3n [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","_joinchat":[],"footnotes":""},"categories":[3415],"tags":[],"class_list":["post-369728","post","type-post","status-publish","format-standard","hentry","category-notas-de-parches"],"_links":{"self":[{"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/posts\/369728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/comments?post=369728"}],"version-history":[{"count":8,"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/posts\/369728\/revisions"}],"predecessor-version":[{"id":371258,"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/posts\/369728\/revisions\/371258"}],"wp:attachment":[{"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/media?parent=369728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/categories?post=369728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pandorafms.com\/es\/wp-json\/wp\/v2\/tags?post=369728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}