4.9.1 Release notes - 17 October 2024

This section lists the changes in version 4.9.1. Every update of the Wazuh solution is cumulative and includes all enhancements and fixes from previous releases.

What's new

This release includes new features or enhancements as the following:

Wazuh manager

  • #24110 Improved provisioning method for wazuh-keystore to enhance security.

Wazuh agent

  • #25652 Added support for macOS 15 "Sequoia" in Wazuh Agent.

RESTful API

  • #26103 Changed the error status code thrown when basic services are down to 500.

Wazuh dashboard

  • #6977 Added feature to filter by field in the events table rows.

  • #6981 Changed the text of the query limit tooltip.

  • #6919 Upgraded the axios dependency to 1.7.4.

  • #6954 Improved MITRE ATT&CK intelligence flyout details readability.

  • #6984 Upgraded Event-tab column selector to show picked columns first.

  • #6960 Changed vulnerabilities.reference to links in Vulnerability Detection > Inventory columns.

  • #6982 Upgraded the follow-redirects dependency to 1.15.6.

  • #6956 Changed many loading spinners in some views to loading search progress.

  • #6999 Removed the XML autoformat function group configuration due to performance issues.

  • #7023 Removed the PDF report footer year.

  • #7086 Removed data grid tables from Threat Hunting dashboard, GitHub panel, and Office365 panel.

Packages

  • #3111 Added offline installation assistant import for the downloaded GPG Wazuh key.

  • #3098 Changed version to tag reference in source_branch references.

  • #3118 Changed Filebeat passwords only when installing Wazuh Server or changing passwords.

  • #3119 Updated SECURITY.md format.

  • #3121 Added stage parameter in bump_version script.

Resolved issues

This release resolves known issues as the following:

Wazuh manager

  • #24909 Fixed vulnerability detector issue where RPM upgrade wouldn't download new content.

  • #25667 Fixed uncaught exception at Keystore test tool.

  • #25705 Replaced eval calls with ast.literal_eval.

  • #26277 Fixed the cluster being disabled by default when loading configurations.

  • #25945 Added support for ARM packages for wazuh-manager.

Wazuh agent

  • #24910 Fixed agent crash on Windows version 4.8.0.

  • #25209 Fixed data race conditions at FIM's run_check.

  • #24376 Fixed Windows agent crashes related to syscollector.dll.

  • #25445 Fixed errors related to the libatomic.a library on AIX 7.X.

  • #24932 Fixed errors in Windows Agent where EvtFormatMessage returned errors 15027 and 15033.

  • #25459 Fixed FIM issue where it couldn't fetch group entries longer than 1024 bytes.

  • #25469 Fixed Wazuh Agent crash at syscollector.

  • #23528 Fixed a bug in the processed dates in the AWS module related to the AWS Config type.

  • #24694 Fixed an error in Custom Logs Buckets when parsing a CSV file that exceeds a certain size.

  • #26108 Fixed macOS syslog and ULS not configured out-of-the-box.

RESTful API

  • #25764 Fixed requests logging to obtain the hash_auth_context from JWT tokens.

  • #25216 Enabled API to listen to both IPv4 and IPv6 stacks.

Wazuh dashboard

  • #6933 Fixed issue causing vulnerability dashboard to fail loading for read-only users.

  • #6905 Fixed the temporal directory variable in the command to deploy a new Windows agent.

  • #6906 Fixed an error in the command to deploy a new macOS agent that could cause the registration password to have a wrong value due to a \n inclusion.

  • #6901 Fixed rendering of an active response as disabled when it is active.

  • #6908 Fixed an error in Dev Tools when using payload properties as arrays.

  • #6987 Fixed font size in tables used in the events tab, the Threat hunting dashboard tab, and the Vulnerabilities inventory tab.

  • #6983 Fixed missing link to Vulnerabilities detection and Office 365 in the agent menu of Endpoints Summary.

  • #6983 Fixed missing options depending on agent operating system in the agent configuration report.

  • #6989 Fixed a style issue that affected the Discover plugin.

  • #6995 Fixed a problem updating the API host registry in the GET /api/check-stored-api.

  • #7019 Fixed the Open report button on the toast and the Download report icon in the reporting table in Safari.

  • #7015 Fixed style issue when unpinning an agent in the endpoint summary section.

  • #7021 Fixed overflow style on a long value filter.

  • #7056 Fixed buttons enabled for a read-only user in Endpoint groups section.

  • #7090 Fixed the automatic page refresh in dashboards and prevented duplicate requests.

Packages

  • #3110 Fixed bug when changing the Filebeat URL in the Installation Assistant.

Changelogs

The repository changelogs provide more details about the changes.

Product repositories

Auxiliary repositories