Upgrade Recommendations
-
If you have not upgraded to 3.6.0 or 3.6.1 yet, upgrade directly from 3.5.x to 3.6.4 to get 3.6 bug-fixes and the latest security fixes in one step.
-
If you are on 3.6.0 or 3.6.1, upgrade to 3.6.4 for the latest security and bug fixes.
-
For a fresh installation, use the 3.6.4 installer package.
Release Notes
3.6.4 is a maintenance release with no new features. The main changes are as follows:
-
Bundled components refreshed versions: OpenSearch 2.19.6-2, OpenSearch-dashboards 2.19.6-2, Node.js 22.23.2, Kafka 3.9.1-2, MongoDB 7.0.40, OpenJDK 17.0.20+8, plus updated service images with security fixes.
-
Web endpoint security has been hardened in 3.6.4 through multiple configuration improvements.
-
The known issue from previous 3.6.1 release related to “Git scans failing on hosts with no Git package in on-prem fresh installation” has been fixed
Vulnerabilities Status
Customer-Installer
|
Component |
Critical
|
High
|
Medium < 90 days |
Low
|
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
1** |
0 |
0 |
|
|
0 |
1* |
1* |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
1* |
2* |
0 |
|
|
0 |
0 |
0 |
0 |
* This vulnerability currently does not have fix available and the component is already updated to the latest version.
** This security fix introduces a breaking change. A non-breaking resolution with refactored code is planned for the next major release.
Kubernetes
|
Component |
Critical
|
High
|
Medium > 90 days |
Low
|
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
1* |
0 |
0 |
|
|
0 |
10** |
74** |
20** |
|
|
1*** |
2*** |
86** |
77** |
|
|
0 |
0 |
0 |
0 |
|
|
0 |
4*** |
2*** |
0 |
|
|
0 |
1** |
1** |
0 |
|
|
0 |
0 |
0 |
0 |
* This security fix introduces a breaking change. A non-breaking resolution with refactored code is planned for the next major release.
** The majority of these vulnerabilities come from OS packages that do not yet have a fixed version available.
*** Currently on the latest version. Resolution depends on a vendor-provided update.
Download Links
Release packages can be download from the download link provided to your organization.
Access credentials are required for all download links.