3.6 3.5 3.4
3.6 3.5 3.4

AgileSec 3.6.4 Release Notes

Upgrade Recommendations

  1. If you have not upgraded to 3.6.0 or 3.6.1 yet, upgrade directly from 3.5.x to 3.6.4 to get 3.6 bug-fixes and the latest security fixes in one step.

  2. If you are on 3.6.0 or 3.6.1, upgrade to 3.6.4 for the latest security and bug fixes.

  3. For a fresh installation, use the 3.6.4 installer package.

Release Notes

3.6.4 is a maintenance release with no new features. The main changes are as follows:

  1. Bundled components refreshed versions: OpenSearch 2.19.6-2, OpenSearch-dashboards 2.19.6-2, Node.js 22.23.2, Kafka 3.9.1-2, MongoDB 7.0.40, OpenJDK 17.0.20+8, plus updated service images with security fixes.

  2. Web endpoint security has been hardened in 3.6.4 through multiple configuration improvements.

  3. The known issue from previous 3.6.1 release related to “Git scans failing on hosts with no Git package in on-prem fresh installation” has been fixed

Vulnerabilities Status

Customer-Installer

Component

Critical
< 30 days

High
< 60 days

Medium < 90 days

Low
< 180 days

analytics-manager

 0

0

0

0

fluentd

0

0

indexing-service

0

0

0

ingestion-service

0

0

0

0

sandbox

0

0

0

0

scheduler-service

0

0

0

0

sm-service

0

0

0

web-api

0

0

0

0

web-ui

0

1**

0

0

kafka

0

1*

1*

0

mongodb-server

0

0

0

0

opensearch

0

0

0

0

opensearch-dashboards

0

1*

2*

0

unified-installer

0

0

0

0

* This vulnerability currently does not have fix available and the component is already updated to the latest version.

** This security fix introduces a breaking change. A non-breaking resolution with refactored code is planned for the next major release.

Kubernetes

Component

Critical
> 30 days

High
> 60 days

Medium > 90 days

Low
> 180 days

analytics-manager

0

0

0

0

fluentd

0

0

0

0

indexing-service

0

0

0

0

ingestion-service

0

0

0

0

sandbox

0

0

0

0

scheduler-service

0

0

0

0

sm-service

0

0

0

0

web-api

0

0

0

0

web-ui

0

1*

0

0

kafka (cp-server)

0

10**

74**

20**

mongodb-server

1***

2***

86**

77**

opensearch

0

0

0

0

opensearch-dashboards

0

4***

2***

0

isg-ingress-nginx-controller

0

1**

1**

0

prometheus-exporter

0

0

0

0

* This security fix introduces a breaking change. A non-breaking resolution with refactored code is planned for the next major release.

** The majority of these vulnerabilities come from OS packages that do not yet have a fixed version available.

*** Currently on the latest version. Resolution depends on a vendor-provided update.

Release packages can be download from the download link provided to your organization.

Access credentials are required for all download links.