Tenable Core 2024 Release Notes
These release notes summarize updates made to Tenable Core in 2024. Downloading and installing the most recent version of the offline ISO image initiates these updates on your Tenable Core machine.
Tip: Tenable recommends applying all offline updates, in order, to your offline Tenable Core machine. Do not skip offline updates.
To update using the Tenable Core offline ISO image, see the documentation for your application:
- Tenable Core + Tenable Nessus
- Tenable Core + Tenable Nessus Network Monitor
- Tenable Core + Tenable Security Center
- Tenable Core + Tenable Web App Scanning
For more information about product updates, see the release notes for your application.
These release notes are listed in reverse chronological order.
October 29, 2024
Tenable is pleased to announce the GA release of Tenable Core + Security Center cross-machine migration. Cross-machine migration lets you migrate data for a different Tenable Security Center system by entering credentials directly in the Tenable Core user interface. This feature enables data synchronization from an existing Tenable Core instance on CentOS 7, Security Center on RHEL (7 or 8), or Oracle 8 to a new Tenable Core setup running on an Oracle 8-based operating system. Available for Security Center versions below 6.5.0.
For more information, refer to the Cross-Machine Migration page in the Tenable Core documentation.
Q3 2024
-
Update to prevent the wizard user's password from expiring.
-
Fixed an issue that prevented downloading CA files from the SSL/TLS Certificates page in the Tenable Core user interface.
Oracle 8 security updates:
ELSA-2024-4620 Important libndp security update
ELSA-2024-4617 Important qt5-qtbase security update
ELSA-2024-4567 Important java-11-openjdk security update
ELSA-2024-5101 Important kernel security update
ELSA-2024-5079 Moderate libtiff security update
ELSA-2024-12580 Moderate linux-firmware security update
ELSA-2024-5530 Important python-setuptools security update
ELSA-2024-5524 Important bind security update
ELSA-2024-5258 Important container-tools:ol8 security update
ELSA-2024-5654 Moderate curl security update
ELSA-2024-5312 Moderate krb5 security update
ELSA-2024-5309 Moderate python-urllib3 security update
ELSA-2024-5299 Moderate wget security update
ELSA-2024-5294 Moderate jose security update
ELSA-2024-6422 Important bubblewrap and flatpak security update
ELSA-2024-7000 Important kernel security update
ELSA-2024-6837 Important pcp security update
ELSA-2024-6989 Moderate expat security update
ELSA-2024-6987 Moderate emacs security update
ELSA-2024-6975 Moderate python3 security update
ELSA-2024-6969 Moderate container-tools:ol8 security update
ELSA-2024-6963 Moderate gtk3 security update
ELSA-2024-7848 Low openssl security update
Oracle 8 updates:
ELBA-2024-25034 tcpreplay Bug Fix update
ELBA-2024-24935 tcpreplay Bug Fix update
ELBA-2024-12556 dnf-plugin-spacewalk bug fix update
ELBA-2024-12553 chrony bug fix update
ELBA-2024-12544 sos bug fix update
ELBA-2024-12543 grubby bug fix update
ELBA-2024-12541 keyutils bug fix update
ELBA-2024-4266 kexec-tools bug fix update
ELBA-2024-12572 mdadm bug fix update
ELBA-2024-12563 chkconfig bug fix update
ELBA-2024-5736 ca-certificates bug fix and enhancement update
ELBA-2024-5311 firewalld bug fix and enhancement update
ELBA-2024-5310 openssh bug fix update
ELBA-2024-5308 libdnf bug fix update
ELBA-2024-5307 sssd bug fix update
ELBA-2024-5301 cloud-init bug fix update
ELBA-2024-5295 mesa bug fix and enhancement update
ELBA-2024-12597 aardvark-dns bug fix update
ELBA-2024-12586 dnf-plugin-spacewalk bug fix update
ELBA-2024-5915 sos bug fix and enhancement update
ELBA-2024-5834 glibc bug fix update
ELBA-2024-12638 audit bug fix update
ELBA-2024-12621 initscripts bug fix update
ELBA-2024-12615 mdadm bug fix update
ELBA-2024-6988 glibc bug fix update
ELBA-2024-6985 avahi bug fix update
ELBA-2024-6984 firewalld bug fix and enhancement update
ELBA-2024-6983 libuser bug fix and enhancement update
ELBA-2024-6981 libldb bug fix update
ELBA-2024-6980 kexec-tools bug fix update
ELBA-2024-6976 findutils bug fix update
ELBA-2024-6974 libX11 bug fix update
ELBA-2024-6970 cloud-init bug fix and enhancement update
ELBA-2024-6967 xmlsec1 bug fix update
ELBA-2024-6680 nss bug fix and enhancement update
ELBA-2024-6977 systemd bug fix update
ELBA-2024-12725 rpm bug fix update
ELBA-2024-12720 sos bug fix update
Type | Reference |
---|---|
Oracle Linux 8 : linux-firmware (ELSA-2024-12580) |
CVE-2023-31315 |
Oracle Linux 8 / 9 : java-11-openjdk (ELSA-2024-4567) |
CVE-2024-21131 |
Oracle Linux 8 : qt5-qtbase (ELSA-2024-4617) |
CVE-2024-39936 |
Oracle Linux 8 : libndp (ELSA-2024-4620) |
CVE-2024-5564 |
Oracle Linux 8 : libtiff (ELSA-2024-5079) |
CVE-2018-15209 |
Oracle Linux 8 : kernel (ELSA-2024-5101) |
CVE-2021-46939 |
Oracle Linux 8 : container-tools:ol8 (ELSA-2024-5258) |
CVE-2023-45290 |
Oracle Linux 8 : jose (ELSA-2024-5294) |
CVE-2023-50967 |
Oracle Linux 8 : wget (ELSA-2024-5299) |
CVE-2024-38428 |
Oracle Linux 8 : python-urllib3 (ELSA-2024-5309) |
CVE-2024-37891 |
Oracle Linux 8 : krb5 (ELSA-2024-5312) |
CVE-2024-37370 |
Oracle Linux 8 : bind (ELSA-2024-5524) |
CVE-2024-1737 |
Oracle Linux 8 : python-setuptools (ELSA-2024-5530) |
CVE-2024-6345 |
Oracle Linux 8 : curl (ELSA-2024-5654) |
CVE-2024-2398 |
Oracle Linux 8 : bubblewrap / and / flatpak (ELSA-2024-6422) |
CVE-2024-42472 |
Oracle Linux 8 : pcp (ELSA-2024-6837) |
CVE-2024-45769 |
Oracle Linux 8 : gtk3 (ELSA-2024-6963) |
CVE-2024-6655 |
Oracle Linux 8 : container-tools:ol8 (ELSA-2024-6969) |
CVE-2023-45290 |
Oracle Linux 8 : python3 (ELSA-2024-6975) |
CVE-2024-4032 |
Oracle Linux 8 : emacs (ELSA-2024-6987) |
CVE-2024-30203 |
Oracle Linux 8 : expat (ELSA-2024-6989) |
CVE-2024-45490 |
Oracle Linux 8 : kernel (ELSA-2024-7000) |
CVE-2021-46984 |
Oracle Linux 8 : openssl (ELSA-2024-7848) |
CVE-2024-5535 |
Q2 2024
-
Tenable Core + OT Security instances are now built with 2GB space on /tmp.
-
Tenable Core + OT Security instances now include the NetworkManager-config-server package which ensures that network interfaces remain available if they are physically disconnected from the network.
-
Remote hosts added in the webui are no longer lost on logout.
-
It is now possible use Tenable Core OL8 installer ISOs on pre-existing Tenable Core EL7 virtual machines to install in place when a machine needs to be reused for process or firewall reasons. All data from the old machine is lost. Temporarily decreasing the machine’s memory before booting the installer ISO prevents the installer from making a larger than needed swap partition. Consider expanding storage after a migration, although for managed scanners this may not be needed. The installer uses the first disk only. If you have previously expanded storage by adding additional disks, you need to reformat the extra disks after the migration and reassign the storage to the system by following the Add or Expand Disk Space topic in the Tenable Core User Guide.
Oracle 8 security updates:
ELSA-2024-1822 Moderate java-11-openjdk security update
ELSA-2024-1902 Important shim security update
ELSA-2024-2084 Important container-tools:4.0 security update
ELSA-2024-2098 Important container-tools:ol8 security and bug fix update
ELSA-2024-2722 Important glibc security update
ELSA-2024-3269 Important glibc security update
ELSA-2024-3271 Important bind and dhcp security update
ELSA-2024-3344 Important glibc security update
ELSA-2024-3347 Important python3 security update
ELSA-2024-3254 Important container-tools:ol8 security update
ELSA-2024-3264 Important pcp security update
ELSA-2024-2973 Moderate libX11 security update
ELSA-2024-2980 Moderate harfbuzz security update
ELSA-2024-2988 Moderate container-tools:ol8 security update
ELSA-2024-3056 Moderate qt5-qtbase security update
ELSA-2024-3102 Moderate python-jinja2 security update
ELSA-2024-3128 Moderate perl:5.32 security update
ELSA-2024-3138 Moderate kernel security, bug fix, and enhancement update
ELSA-2024-3139 Moderate squashfs-tools security update
ELSA-2024-3184 Moderate grub2 security update
ELSA-2024-3203 Moderate systemd security update
ELSA-2024-3214 Moderate gmp security update
ELSA-2024-3268 Low krb5 security update
ELSA-2024-3270 Moderate sssd security update
ELSA-2024-3341 Moderate gdk-pixbuf2 security update
ELSA-2024-3667 Moderate cockpit security update
ELSA-2024-3626 Moderate libxml2 security update
ELSA-2024-3618 Moderate kernel update
ELSA-2024-3961 Important flatpak security update
ELSA-2024-4256 Important less security update
ELSA-2024-4211 Important kernel security and bug fix update
ELSA-2024-4265 Moderate cups security update
ELSA-2024-4260 Moderate python-idna security update
ELSA-2024-4259 Moderate xmlrpc-c security and bug fix update
ELSA-2024-4252 Moderate nghttp2 security update
ELSA-2024-4247 Moderate libuv security update
ELSA-2024-4231 Moderate python-jinja2 security update
ELSA-2024-4264 Low openldap security update
ELSA-2024-4249 Low c-ares security update
Oracle 8 updates:
ELBA-2024-12333 selinux-policy bug fix update
ELBA-2024-12339 aardvark-dns bug fix update
ELBA-2024-2056 openscap bug fix and enhancement update
ELBA-2024-12379 linux-firmware bug fix update
ELBA-2024-12381 sos bug fix update
ELBA-2024-2964 cloud-init bug fix and enhancement update
ELBA-2024-2965 open-vm-tools bug fix and enhancement update
ELBA-2024-2967 pixman bug fix and enhancement update
ELBA-2024-2984 flatpak bug fix and enhancement update
ELBA-2024-2993 jq bug fix and enhancement update
ELBA-2024-2998 libblockdev bug fix and enhancement update
ELBA-2024-3000 cockpit-appstream bug fix and enhancement update
ELBA-2024-3016 tcpdump bug fix and enhancement update
ELBA-2024-3023 python36:3.6 bug fix and enhancement update
ELBA-2024-3027 mesa bug fix and enhancement update
ELBA-2024-3029 tracer bug fix and enhancement update
ELBA-2024-3031 setroubleshoot bug fix and enhancement update
ELBA-2024-3033 alsa-lib bug fix and enhancement update
ELBA-2024-3048 anaconda bug fix and enhancement update
ELBA-2024-3052 oniguruma bug fix and enhancement update
ELBA-2024-3091 sysstat bug fix and enhancement update
ELBA-2024-3122 pyserial bug fix and enhancement update
ELBA-2024-3124 ksh bug fix and enhancement update
ELBA-2024-3126 libglvnd bug fix and enhancement update
ELBA-2024-3135 redhat-release bug fix and enhancement update
ELBA-2024-3136 libsoup bug fix and enhancement update
ELBA-2024-3140 kexec-tools bug fix and enhancement update
ELBA-2024-3142 numactl bug fix and enhancement update
ELBA-2024-3143 selinux-policy bug fix and enhancement update
ELBA-2024-3144 gcc bug fix and enhancement update
ELBA-2024-3150 python-urllib3 bug fix and enhancement update
ELBA-2024-3152 glibc bug fix and enhancement update
ELBA-2024-3154 curl bug fix and enhancement update
ELBA-2024-3155 kmod bug fix and enhancement update
ELBA-2024-3156 rpm bug fix and enhancement update
ELBA-2024-3157 cockpit bug fix and enhancement update
ELBA-2024-3159 python-linux-procfs bug fix and enhancement update
ELBA-2024-3161 libdnf bug fix and enhancement update
ELBA-2024-3162 shadow-utils bug fix and enhancement update
ELBA-2024-3164 dnf bug fix and enhancement update
ELBA-2024-3165 cups bug fix and enhancement update
ELBA-2024-3169 dnf-plugins-core bug fix and enhancement update
ELBA-2024-3174 findutils bug fix and enhancement update
ELBA-2024-3180 dracut bug fix and enhancement update
ELBA-2024-3181 tpm2-tss bug fix and enhancement update
ELBA-2024-3183 device-mapper-multipath bug fix and enhancement update
ELBA-2024-3186 libldb bug fix and enhancement update
ELBA-2024-3187 libtevent bug fix and enhancement update
ELBA-2024-3188 libtdb bug fix and enhancement update
ELBA-2024-3189 libtalloc bug fix and enhancement update
ELBA-2024-3191 p11-kit bug fix and enhancement update
ELBA-2024-3192 python3 bug fix and enhancement update
ELBA-2024-3198 shared-mime-info bug fix and enhancement update
ELBA-2024-3204 grubby bug fix and enhancement update
ELBA-2024-3210 dmidecode bug fix and enhancement update
ELBA-2024-3212 chrony bug fix and enhancement update
ELBA-2024-3216 net-snmp bug fix and enhancement update
ELBA-2024-3218 policycoreutils bug fix and enhancement update
ELBA-2024-3219 gpgme bug fix and enhancement update
ELBA-2024-3220 python-pip bug fix and enhancement update
ELBA-2024-3221 tuned bug fix and enhancement update
ELBA-2024-3222 hwdata bug fix and enhancement update
ELBA-2024-3223 fuse bug fix and enhancement update
ELBA-2024-3224 util-linux bug fix and enhancement update
ELBA-2024-3226 bind bug fix and enhancement update
ELBA-2024-3228 lvm2 bug fix and enhancement update
ELBA-2024-3231 realmd bug fix and enhancement update
ELBA-2024-3234 libtirpc bug fix and enhancement update
ELBA-2024-3236 expat bug fix and enhancement update
ELBA-2024-3237 bash bug fix and enhancement update
ELBA-2024-3262 nss bug fix update
ELBA-2024-3272 gcc bug fix update
ELBA-2024-3274 sos update
ELBA-2024-3358 polkit bug fix update
ELBA-2024-3381 tuned bug fix update
ELEA-2024-3098 new module: mariadb:10.11
ELEA-2024-3235 iproute bug fix and enhancement update
ELBA-2024-12434 sos bug fix update
ELBA-2024-12413 systemd bug fix update
ELBA-2024-4253 policycoreutils bug fix update
ELBA-2024-4251 pam bug fix update
ELBA-2024-4250 libtirpc bug fix update
ELBA-2024-4240 google-noto-cjk-fonts bug fix update
ELBA-2024-4236 sysstat bug fix update
ELBA-2024-4234 jq update
ELBA-2024-4049 sos bug fix and enhancement update
ELBA-2024-12459 pam bug fix update
ELBA-2024-12455 pam bug fix update
ELBA-2024-12453 perl bug fix update
ELBA-2024-4263 krb5 bug fix update
ELBA-2024-4255 systemd update
ELBA-2024-4230 cockpit-appstream bug fix update
ELBA-2024-4229 cloud-init bug fix update
ELBA-2024-12482 linux-firmware bug fix update
ELBA-2024-12476 sos bug fix update
CentOS7 security updates:
CESA-2024:1821 Moderate CentOS 7 java-11-openjdk update
CESA-2024:2004 Important CentOS 7 kernel update
CESA-2024:3588 Important CentOS 7 glibc update
CESA-2024:3669 Important CentOS 7 less update
CESA-2024:3741 Important CentOS 7 bind and dhcp update
CentOS7 updates:
CEBA-2024:3589 CentOS 7 kernel update
Type | Reference |
---|---|
Oracle Linux 8 / 9 : java-11-openjdk (ELSA-2024-1822) |
CVE-2024-21011 |
Oracle Linux 8 : shim (ELSA-2024-1902) |
CVE-2023-40546 |
Oracle Linux 8 : container-tools:4.0 (ELSA-2024-2084) |
CVE-2024-1753 |
Oracle Linux 8 : container-tools:ol8 (ELSA-2024-2098) |
CVE-2024-1753 |
Oracle Linux 8 : glibc (ELSA-2024-2722) |
CVE-2024-2961 |
Oracle Linux 8 : libX11 (ELSA-2024-2973) |
CVE-2023-43785 |
Oracle Linux 8 : harfbuzz (ELSA-2024-2980) |
CVE-2023-25193 |
Oracle Linux 8 : container-tools:ol8 (ELSA-2024-2988) |
CVE-2018-25091 |
Oracle Linux 8 : qt5-qtbase (ELSA-2024-3056) |
CVE-2023-51714 |
Oracle Linux 8 : python-jinja2 (ELSA-2024-3102) |
CVE-2024-22195 |
Oracle Linux 8 : perl:5.32 (ELSA-2024-3128) |
CVE-2023-47038 |
Oracle Linux 8 : kernel (ELSA-2024-3138) |
CVE-2019-13631 |
Oracle Linux 8 : squashfs-tools (ELSA-2024-3139) |
CVE-2021-40153 |
Oracle Linux 8 : grub2 (ELSA-2024-3184) |
CVE-2023-4692 |
Oracle Linux 8 : systemd (ELSA-2024-3203) |
CVE-2023-7008 |
Oracle Linux 8 : gmp (ELSA-2024-3214) |
CVE-2021-43618 |
Oracle Linux 8 : container-tools:ol8 (ELSA-2024-3254) |
CVE-2022-2880 |
Oracle Linux 8 : pcp (ELSA-2024-3264) |
CVE-2024-3019 |
Oracle Linux 8 : krb5 (ELSA-2024-3268) |
CVE-2024-26458 |
Oracle Linux 8 : glibc (ELSA-2024-3269) |
CVE-2024-2961 |
Oracle Linux 8 : sssd (ELSA-2024-3270) |
CVE-2023-3758 |
Oracle Linux 8 : bind / and / dhcp (ELSA-2024-3271) |
CVE-2023-4408 |
Oracle Linux 8 : gdk-pixbuf2 (ELSA-2024-3341) |
CVE-2022-48622 |
Oracle Linux 8 : glibc (ELSA-2024-3344) |
CVE-2024-33599 |
Oracle Linux 8 : python3 (ELSA-2024-3347) | CVE-2023-6597 CVE-2024-0450 |
Oracle Linux 8 : kernel (ELSA-2024-3618) | CVE-2019-25162 CVE-2020-36777 CVE-2021-46934 CVE-2021-47013 CVE-2021-47055 CVE-2021-47118 CVE-2021-47153 CVE-2021-47171 CVE-2021-47185 CVE-2022-48627 CVE-2022-48669 CVE-2023-52439 CVE-2023-52445 CVE-2023-52477 CVE-2023-52513 CVE-2023-52520 CVE-2023-52528 CVE-2023-52565 CVE-2023-52578 CVE-2023-52594 CVE-2023-52595 CVE-2023-52598 CVE-2023-52606 CVE-2023-52607 CVE-2023-52610 CVE-2023-6240 CVE-2024-0340 CVE-2024-23307 CVE-2024-25744 CVE-2024-26593 CVE-2024-26603 CVE-2024-26610 CVE-2024-26615 CVE-2024-26642 CVE-2024-26643 CVE-2024-26659 CVE-2024-26664 CVE-2024-26693 CVE-2024-26694 CVE-2024-26743 CVE-2024-26744 CVE-2024-26779 CVE-2024-26872 CVE-2024-26892 CVE-2024-26897 CVE-2024-26901 CVE-2024-26919 CVE-2024-26933 CVE-2024-26934 CVE-2024-26964 CVE-2024-26973 CVE-2024-26993 CVE-2024-27014 CVE-2024-27048 CVE-2024-27052 CVE-2024-27056 CVE-2024-27059 |
Oracle Linux 8 : libxml2 (ELSA-2024-3626) | CVE-2024-25062 |
Oracle Linux 8 : cockpit (ELSA-2024-3667) | CVE-2024-2947 |
Oracle Linux 8 : flatpak (ELSA-2024-3961) | CVE-2024-32462 |
Oracle Linux 8 : kernel (ELSA-2024-4211) | CVE-2020-26555 CVE-2021-46909 CVE-2021-46972 CVE-2021-47069 CVE-2021-47073 CVE-2021-47236 CVE-2021-47310 CVE-2021-47311 CVE-2021-47353 CVE-2021-47356 CVE-2021-47456 CVE-2021-47495 CVE-2023-5090 CVE-2023-52464 CVE-2023-52560 CVE-2023-52615 CVE-2023-52626 CVE-2023-52667 CVE-2023-52669 CVE-2023-52675 CVE-2023-52686 CVE-2023-52700 CVE-2023-52703 CVE-2023-52781 CVE-2023-52813 CVE-2023-52835 CVE-2023-52877 CVE-2023-52878 CVE-2023-52881 CVE-2024-26583 CVE-2024-26584 CVE-2024-26585 CVE-2024-26656 CVE-2024-26675 CVE-2024-26735 CVE-2024-26759 CVE-2024-26801 CVE-2024-26804 CVE-2024-26826 CVE-2024-26859 CVE-2024-26906 CVE-2024-26907 CVE-2024-26974 CVE-2024-26982 CVE-2024-27397 CVE-2024-27410 CVE-2024-35789 CVE-2024-35835 CVE-2024-35838 CVE-2024-35845 CVE-2024-35852 CVE-2024-35853 CVE-2024-35854 CVE-2024-35855 CVE-2024-35888 CVE-2024-35890 CVE-2024-35958 CVE-2024-35959 CVE-2024-35960 CVE-2024-36004 CVE-2024-36007 |
Oracle Linux 8 : python-jinja2 (ELSA-2024-4231) | CVE-2024-34064 |
Oracle Linux 8 : libuv (ELSA-2024-4247) | CVE-2024-24806 |
Oracle Linux 8 : c-ares (ELSA-2024-4249) | CVE-2024-25629 |
Oracle Linux 8 : nghttp2 (ELSA-2024-4252) | CVE-2024-28182 |
Oracle Linux 8 : less (ELSA-2024-4256) | CVE-2022-48624 CVE-2024-32487 |
Oracle Linux 8 : xmlrpc-c (ELSA-2024-4259) | CVE-2023-52425 |
Oracle Linux 8 : python-idna (ELSA-2024-4260) | CVE-2024-3651 |
Oracle Linux 8 : openldap (ELSA-2024-4264) | CVE-2023-2953 |
Oracle Linux 8 : cups (ELSA-2024-4265) | CVE-2024-35235 |
Type | Reference |
---|---|
CentOS 7 : java-11-openjdk (RHSA-2024:1821) |
CVE-2024-21011 |
CentOS 7 : kernel (RHSA-2024:2004) |
CVE-2020-36558 |
CentOS 7 : bind, bind-dyndb-ldap, and dhcp (RHSA-2024:3741) |
CVE-2023-4408 |
CentOS 7 : glibc (RHSA-2024:3741) |
CVE-2023-4408 |
RHEL 7 : java-11-openjdk (RHSA-2024:1821) |
CVE-2024-21011 |
RHEL 7 : kernel (RHSA-2024:2004) |
CVE-2020-36558 |
RHEL 7 : glibc (RHSA-2024:3588) |
CVE-2024-2961 |
RHEL 7 : less (RHSA-2024:3669) |
CVE-2024-32487 |
RHEL 7 : bind, bind-dyndb-ldap, and dhcp (RHSA-2024:3741) |
CVE-2023-4408 |
June 4, 2024
Tenable is pleased to announce the GA release of Tenable Core + Nessus Expert w/Web Application Scanning. Now customers can enable Tenable Nessus Expert on Tenable Core with the ability to run the Web Application Scanning portion of the product. For more information, refer to the Enable Docker for Web Application Scanning with Nessus Expert in the Tenable Core documentation.
Q1 2024
-
Tenable Core systems based on Oracle Linux 8 now supports selecting stronger hash functions (up to SHA-512) on the SNMP page of the user interface.
-
Tenable Core + Tenable OT Security supports backup and restore in the Tenable Core user interface. Only backups taken from that user interface can be restored there (backups taken within Tenable OT Security cannot be restored here).
-
New Tenable OT Security Enterprise Manager instances no longer rename network interfaces to the nicX convention. Enterprise Manager is available on the network interface chosen at install-time in the user interface. Existing EM instances continue to listen on nic0.
-
Tenable Core now examines the checksum baked into offline update ISOs and logs a message if a corrupt ISO is placed in the offline iso location under /srv.
-
SensorProxy application update to 1.0.9
Oracle 8 security updates:
ELSA-2024-0266 Important java-11-openjdk security update
ELSA-2024-12079 Important python-cryptography security update
ELSA-2024-0155 Moderate gnutls security update
ELSA-2024-0253 Moderate sqlite security update
ELSA-2024-0256 Moderate python3 security update
ELSA-2024-0748 Important container-tools:4.0 security update
ELSA-2024-0752 Important container-tools:ol8 security update
ELSA-2024-0627 Moderate gnutls security update
ELSA-2024-0628 Moderate libssh security update
ELSA-2024-0647 Moderate rpm security update
ELSA-2024-0768 Moderate libmaxminddb security update
ELSA-2024-0769 Moderate tcpdump security update
ELSA-2024-0786 Moderate nss security update
ELSA-2024-0811 Moderate sudo security update
ELSA-2024-12135 Moderate gnutls security update
ELSA-2024-12164 Moderate openssh security update
ELSA-2024-0965 Important unbound security update
ELSA-2024-12187 Important kernel security update
ELSA-2024-0889 Moderate oniguruma security update
ELSA-2024-12191 Moderate podman security update
ELSA-2024-12266 Important kernel security update
ELSA-2024-1607 Important kernel security, bug fix, and enhancement update
ELSA-2024-1751 Important unbound security update
ELSA-2024-1782 Important bind and dhcp security update
ELSA-2024-1601 Moderate curl security and bug fix update
ELSA-2024-1610 Moderate less security update
ELSA-2024-1615 Moderate expat security update
ELSA-2024-1784 Moderate gnutls security update
Oracle 8 updates:
ELBA-2024-0111 selinux-policy bug fix update
ELBA-2024-0112 NetworkManager bug fix update
ELBA-2024-0117 libcap bug fix update
ELBA-2024-0124 cloud-init bug fix update
ELBA-2024-12074 gnutls bug fix update
ELBA-2024-12081 gcc bug fix update
ELBA-2024-12090 cloud-init bug fix update
ELBA-2024-0721 sos bugfix and enhancement update
ELBA-2024-0762 tzdata bug fix and enhancement update
ELBA-2024-12091 rpm bug fix update
ELBA-2024-12142 nfs-utils bug fix update
ELBA-2024-12145 kexec-tools bug fix update
ELBA-2024-12161 linux-firmware bug fix update
ELBA-2024-0898 python-cryptography bug fix update
ELBA-2024-0899 sssd bug fix update
ELBA-2024-12168 gcc bug fix update
ELBA-2024-12178 mdadm bug fix update
ELBA-2024-12179 bcache-tools bug fix update
ELBA-2024-12181 systemd bug fix update
ELBA-2024-12183 sos bug fix update
ELBA-2024-12184 binutils bug fix update
ELBA-2024-12231 selinux-policy bug fix updateS
ELBA-2024-12241 cloud-init bug fix update
ELBA-2024-12242 pam bug fix update
ELBA-2024-12244 sos bug fix update
ELBA-2024-19555 tcpreplay Bug Fix update
ELBA-2024-19558 tcpreplay Bug Fix update
ELBA-2024-12322 shim bug fix update
ELBA-2024-1596 python3.11-pip bug fix and enhancement update
ELBA-2024-1599 container-tools:ol8 bug fix update
ELBA-2024-1602 nftables bug fix update
ELBA-2024-1603 iptables bug fix update
ELBA-2024-1604 NetworkManager bug fix update
ELBA-2024-1605 perl-HTTP-Tiny bug fix update
ELBA-2024-1606 util-linux bug fix update
ELBA-2024-1609 python-pip bug fix update
ELBA-2024-1739 sos bugfix and enhancement update
ELBA-2024-20140 libbsd Bug Fix update
CentOS7 security updates
CESA-2024:0232 Important CentOS 7 java-11-openjdk Security update
CESA-2024:0346 Important CentOS 7 kernel Security update
CESA-2024:0753 Moderate CentOS 7 linux-firmware update
CESA-2024:1249 Important CentOS 7 kernel update
CentOS7 updates:
CEBA-2024:0350 CentOS 7 net-snmp BugFix update
CEBA-2024:0762 CentOS 7 tzdata update
CEBA-2024:1275 CentOS 7 lm_sensors update
CEBA-2024:1277 CentOS 7 libX11 update
CEBA-2024:0721 CentOS 7 sos BugFix update
Type | Reference |
---|---|
CentOS 7 : java-11-openjdk (RHSA-2024:0232) |
CVE-2024-20918 |
CentOS 7 : kernel (RHSA-2024:0346) |
CVE-2023-42753 |
CentOS 7 : kernel (RHSA-2024:1249) |
CVE-2022-42896 |
CentOS 7 : linux-firmware (RHSA-2024:0753) |
CVE-2023-20592 |
RHEL 7 : java-11-openjdk (RHSA-2024:0232) |
CVE-2024-20918 |
RHEL 7 : kernel (RHSA-2024:0346) |
CVE-2023-42753 |
RHEL 7 : kernel (RHSA-2024:1249) |
CVE-2022-42896 |
Type | Reference |
---|---|
Oracle Linux 8 : gnutls (ELSA-2024-0155) |
CVE-2023-5981 |
Oracle Linux 8 : sqlite (ELSA-2024-0253) |
CVE-2023-7104 |
Oracle Linux 8 : python3 (ELSA-2024-0256) |
CVE-2023-27043 |
Oracle Linux 8 / 9 : java-11-openjdk (ELSA-2024-0266) |
CVE-2024-20918 |
Oracle Linux 8 : gnutls (ELSA-2024-0627) |
CVE-2024-0553 |
Oracle Linux 8 : libssh (ELSA-2024-0628) |
CVE-2023-48795 |
Oracle Linux 8 : rpm (ELSA-2024-0647) |
CVE-2021-35937 |
Oracle Linux 8 : container-tools:4.0 (ELSA-2024-0748) |
CVE-2023-45287 |
Oracle Linux 8 : container-tools:ol8 (ELSA-2024-0752) |
CVE-2024-21626 |
Oracle Linux 8 : libmaxminddb (ELSA-2024-0768) |
CVE-2020-28241 |
Oracle Linux 8 : tcpdump (ELSA-2024-0769) |
CVE-2021-41043 |
Oracle Linux 8 : nss (ELSA-2024-0786) |
CVE-2023-6135 |
Oracle Linux 8 / 9 : sudo (ELSA-2024-0811) |
CVE-2023-28486 |
Oracle Linux 8 : oniguruma (ELSA-2024-0889) |
CVE-2019-13224 |
Oracle Linux 8 : unbound (ELSA-2024-0965) |
CVE-2023-50387 |
Oracle Linux 8 / 9 : python-cryptography (ELSA-2024-12079) |
CVE-2023-49083 |
Oracle Linux 8 : gnutls (ELSA-2024-12135) |
CVE-2024-0553 |
Oracle Linux 8 : openssh (ELSA-2024-12164) |
CVE-2023-48795 |
Oracle Linux 8 : kernel (ELSA-2024-12187) |
CVE-2023-2176 |
Oracle Linux 8 : podman (ELSA-2024-12191) | CVE-2023-39326 |
Oracle Linux 8 : kernel (ELSA-2024-12266) | CVE-2024-1086 |
Oracle Linux 8 : curl (ELSA-2024-1601) | CVE-2023-28322 CVE-2023-38546 CVE-2023-46218 |
Oracle Linux 8 : kernel (ELSA-2024-1607) | CVE-2021-33631 CVE-2022-38096 CVE-2023-51042 CVE-2023-6546 CVE-2023-6931 CVE-2024-0565 CVE-2024-1086 |
Oracle Linux 8 : less (ELSA-2024-1610) | CVE-2022-48624 |
Oracle Linux 8 : expat (ELSA-2024-1615) | CVE-2023-52425 |
Oracle Linux 8 : unbound (ELSA-2024-1751) | CVE-2024-1488 |
Oracle Linux 8 : bind / and / dhcp (ELSA-2024-1782) | CVE-2023-4408 CVE-2023-50387 CVE-2023-50868 |
Oracle Linux 8 : gnutls (ELSA-2024-1784) | CVE-2024-28834 |
Tenable Core + Sensor Proxy
Adding to Tenable's portfolio of Tenable Core-enabled applications, now customers can quickly deploy Sensor Proxy with the ease of functionality that comes with Tenable Core. This general availability release includes the latest version of Sensor Proxy. For more information, refer to the Tenable Core + Sensor Proxy documentation.
-
Sensor Proxy Server Certificates are not available for editing on the "SSL/TLS Certificates" page within the Tenable Core user interface.
Q4 2023
-
Tenable Core systems based on Oracle Linux 8 will no longer automatically mount Tenable Core Offline Updates for systems based on CentOS 7 and Tenable Core systems based on CentOS 7 will no longer automatically mount Offline Updates for systems based on Oracle Linux 8.
-
It is now possible to choose local storage rather than remote storage for storing any backups taken on Tenable Core. If local backups are stored on the system, they can be listed and downloaded on the Backup/Restore page.
-
It is now possible to restore backups stored in local-backup storage using the "Restore from local backup storage" button in the Backup/Restore page of the Tenable Core webui.
-
The Tenable Core installer now works in cases where the installer drive is found before the intended destination drive. It is also now possible to override the destination drive by specifying it on the GRUB command line (tc.destdisk=sdd).
Oracle 8 security updates:
ELSA-2023-12851 Important glibc security update
ELSA-2023-5474 Important bind security update
ELSA-2023-5683 Important mariadb:10.5 security update
ELSA-2023-5997 Important python3 security update
ELSA-2023-5742 Moderate java-11-openjdk security and bug fix update
ELSA-2023-6236 Moderate binutils security update
ELSA-2023-5455 Important glibc security update
ELSA-2023-5837 Important nghttp2 security update
ELSA-2023-12988 Important microcode_ctl security update
ELSA-2023-7265 important open-vm-tools security update
ELSA-2023-7207 moderate c-ares security update
ELSA-2023-7549 important kernel security and bug fix update
ELSA-2023-7836 Moderate avahi security update
ELSA-2023-7877 Low openssl security update
CESA-2023:5691 Important CentOS 7 bind update
CESA-2023:6823 Important CentOS 7 python3 update
CESA-2023:6885 Important CentOS 7 python update
CESA-2023:7279 Important CentOS 7 open-vm-tools update
CESA-2023:7423 Important CentOS 7 kernel update
CESA-2023:5615 Moderate CentOS 7 libssh2 update
CESA-2023:5736 Moderate CentOS 7 java-11-openjdk update
CESA-2023:7513 Moderate CentOS 7 linux-firmware update
CESA-2023:7743 Low CentOS 7 curl update
ELSA-2024-12069 Important kernel security update
ELSA-2024-0105 Moderate nss security update
ELSA-2024-0114 Moderate python3 security update
ELSA-2024-0116 Moderate python-urllib3 security update
ELSA-2024-0119 Moderate libxml2 security update
ELSA-2024-0131 Moderate pixman security update
Oracle 8 updates:
ELBA-2023-12847 linux-firmware bug fix update
ELBA-2023-12849 gcc bug fix update
ELBA-2023-12927 procps-ng bug fix update
ELBA-2023-12949 systemd bug fix update
ELBA-2023-12951 kexec-tools bug fix update
ELBA-2023-5247 systemd bug fix and enhancement update
ELBA-2023-12856 dnf-plugins-core bug fix update
ELBA-2023-12947 pcp bug fix update
ELEA-2023-7117 microcode_ctl bug fix and enhancement update
ELBA-2023-6792 net-snmp bug fix update
ELBA-2023-6293 sos bugfix update
ELBA-2023-7210 sssd bug fix update
ELBA-2023-13006 linux-firmware bug fix update
ELBA-2023-13007 util-linux bug fix update
ELBA-2023-7211 krb5 bug fix update
ELBA-2023-13030 mdadm bug fix update
ELBA-2023-13031 jq bug fix update
ELBA-2023-13032 systemd bug fix update
ELBA-2023-13035 mdadm bug fix update
ELBA-2023-13036 bcache-tools bug fix update
ELBA-2023-13037 systemd bug fix update
ELBA-2023-13038 lvm2 bug fix update
ELBA-2023-7838 python36:3.6 bug fix update
ELEA-2023-7250 microcode_ctl bug fix and enhancement update
CEBA-2023:5478 CentOS 7 nss bugfix update
CEBA-2023:5623 CentOS 7 ca-certificates bugfix update
CEBA-2023:7426 CentOS 7 xmlsec1 bugfix update
CEBA-2023:7468 CentOS 7 systemd bugfix update
ELBA-2024-0076 tzdata bug fix and enhancement update
CentOS7 security updates
CESA-2023:5691 Important CentOS 7 bind update
CESA-2023:6823 Important CentOS 7 python3 update
CESA-2023:6885 Important CentOS 7 python update
CESA-2023:7279 Important CentOS 7 open-vm-tools update
CESA-2023:7423 Important CentOS 7 kernel update
CESA-2023:5615 Moderate CentOS 7 libssh2 update
CESA-2023:5736 Moderate CentOS 7 java-11-openjdk update
CESA-2023:7513 Moderate CentOS 7 linux-firmware update
CESA-2023:7743 Low CentOS 7 curl update
CentOS7 updates:
CEBA-2023:5478 CentOS 7 nss bugfix update
CEBA-2023:5623 CentOS 7 ca-certificates bugfix update
CEBA-2023:7426 CentOS 7 xmlsec1 bugfix update
CEBA-2023:7468 CentOS 7 systemd bugfix update
Type | Reference |
---|---|
CentOS 7 : libssh2 (RHSA-2023:5615) |
CVE-2020-22218 |
CentOS 7 : bind (RHSA-2023:5691) |
CVE-2023-3341 |
CentOS 7 : java-11-openjdk (RHSA-2023:5736) |
CVE-2023-22081 |
CentOS 7 : python3 (RHSA-2023:6823) |
CVE-2023-40217 |
CentOS 7 : python (RHSA-2023:6885) |
CVE-2023-40217 |
CentOS 7 : open-vm-tools (RHSA-2023:7279) |
CVE-2023-34058 CVE-2023-34059 |
CentOS 7 : kernel (RHSA-2023:7423) |
CVE-2022-40982 CVE-2023-4208 |
CentOS 7 : linux-firmware (RHSA-2023:7513) |
CVE-2023-20569 CVE-2023-20593 |
CentOS 7 : curl (RHSA-2023:7743) |
CVE-2022-43552 |
RHEL 7 : libssh2 (RHSA-2023:5615) |
CVE-2020-22218 |
RHEL 7 : bind (RHSA-2023:5691) |
CVE-2023-3341 |
RHEL 7 : java-11-openjdk (RHSA-2023:5736) |
CVE-2023-22081 |
RHEL 7 : python3 (RHSA-2023:6823) |
CVE-2023-40217 |
RHEL 7 : python (RHSA-2023:6885) |
CVE-2023-40217 |
RHEL 7 : open-vm-tools (RHSA-2023:7279) |
CVE-2023-34058 |
RHEL 7 : kernel (RHSA-2023:7423) |
CVE-2022-40982 |
RHEL 7 : linux-firmware (RHSA-2023:7513) |
CVE-2023-20569 |
RHEL 7 : curl (RHSA-2023:7743) |
CVE-2022-43552 |
Type | Reference |
---|---|
Oracle Linux 8 : glibc (ELSA-2023-12851) |
CVE-2023-4911 |
Oracle Linux 8 : microcode_ctl (ELSA-2023-12988) |
CVE-2023-23583 |
Oracle Linux 8 : glibc (ELSA-2023-5455) |
CVE-2023-4527 |
Oracle Linux 8 : bind (ELSA-2023-5474) |
CVE-2023-3341 |
Oracle Linux 8 : mariadb:10.5 (ELSA-2023-5683) |
CVE-2022-32081 |
Oracle Linux 8 : java-11-openjdk (ELSA-2023-5742) |
CVE-2023-22081 |
Oracle Linux 8 : nghttp2 (ELSA-2023-5837) |
CVE-2023-44487 |
Oracle Linux 8 : python3 (ELSA-2023-5997) |
CVE-2023-40217 |
Oracle Linux 8 : binutils (ELSA-2023-6236) |
CVE-2022-4285 |
Oracle Linux 8 : c-ares (ELSA-2023-7207) |
CVE-2020-22217 |
Oracle Linux 8 : open-vm-tools (ELSA-2023-7265) |
CVE-2023-34058 |
Oracle Linux 8 : kernel (ELSA-2023-7549) |
CVE-2022-45884 |
Oracle Linux 8 : avahi (ELSA-2023-7836) |
CVE-2021-3468 |
Oracle Linux 8 : openssl (ELSA-2023-7877) |
CVE-2023-3446 |
Oracle Linux 8 : nss (ELSA-2024-0105) |
CVE-2023-5388 |
Oracle Linux 8 : python3 (ELSA-2024-0114) |
CVE-2022-48560 |
Oracle Linux 8 : python-urllib3 (ELSA-2024-0116) |
CVE-2023-43804 |
Oracle Linux 8 : libxml2 (ELSA-2024-0119) |
CVE-2023-39615 |
Oracle Linux 8 : kernel (ELSA-2024-12069) |
CVE-2023-2162 |