Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No Update 2.8.0 available

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    7 Posts 5 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pixel24
      last edited by

      Hi all,

      There was a security issue reported with pfSense on a German IT platform (Cross-Site Scripting: Security vulnerabilities in pfSense allow admin cookie theft). See:

      https://www.heise.de/news/Cross-Site-Scripting-Sicherheitsluecken-in-pfSense-ermoeglichen-Admin-Cookieklau-9696756.html

      Furthermore, it's mentioned here that there are already updates available to fix the problem. For the CE version, this would be version 2.8.0. However, this version is not offered in the web UI.

      with best
      pixel24

      GertjanG patient0P S 3 Replies Last reply Reply Quote 1
      • GertjanG
        Gertjan @pixel24
        last edited by

        @pixel24

        The Pathes package doesn't have a solution ready ?

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        P 1 Reply Last reply Reply Quote 0
        • patient0P
          patient0 @pixel24
          last edited by

          @pixel24 there is no update to 2.8.0 yet, the pfSense Plus just came out and I assume it will take a while for CE to be updated.

          But: the System_Patches package probably contains a fixes for it:

          Fix potential stored XSS via services_acb_settings.php "frequency" paramter (pfSense-SA-24_02.webgui, Redmine #15224) 	
          	
          Fix potential XSS due to PHP error display formatting issues (After applying, reboot or use console/ssh menu options 11/16 to restart PHP and the GUI, pfSense-SA-24_03.webgui, Redmine #15263, Redmine #15264) 	
          	
          Fix Potential XSS from jquery-treegrid unit testing files (Once applied, this patch may not offer a revert option, pfSense-SA-24_04.webgui, Redmine #15265) 
          
          1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @pixel24
            last edited by

            See https://forum.netgate.com/topic/187622/system-patches-package-v2-2-10_1 for 2.7.2/23.09.1.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            1 Reply Last reply Reply Quote 0
            • P
              pixel24 @Gertjan
              last edited by

              @Gertjan I've never worked with the Pathes package before. I've always installed updates exclusively through the web UI.

              S S 2 Replies Last reply Reply Quote 0
              • S
                slu @pixel24
                last edited by

                @pixel24
                you can apply the patches over GUI.
                Install System_Patches package and go to System / Patches and apply them all.

                pfSense Gold subscription

                1 Reply Last reply Reply Quote 1
                • S
                  SteveITS Galactic Empire @pixel24
                  last edited by

                  @pixel24 said in No Update 2.8.0 available:

                  @Gertjan I've never worked with the Pathes package before. I've always installed updates exclusively through the web UI.

                  That is for program updates. Netgate releases fixes in between version updates. They are normally included in the next version. They often backport security fixes.

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote ๐Ÿ‘ helpful posts!

                  1 Reply Last reply Reply Quote 1
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.