pfSense Plus¶
Changes in this version of pfSense Plus software.
Aliases / Tables¶
Captive Portal¶
Fixed: Captive Portal authentication failures from usernames containing special characters or long strings can cause ambiguous or confusing log messages #16922
Configuration Backend¶
Changed: Improve handling of OpenSSL encryption passphrase #16958
DHCP (IPv4)¶
Added: Option to control Kea log level #16230
Changed: Kea attempts DNS Registration when Unbound is disabled #16865
Fixed: Daemon configuration manipulation via CR/LF in ISC DHCP settings #16900
Fixed: Potential XSS in DHCPv4 Pool Descriptions #16940
Added: Kea Custom Configuration JSON privilege #16960
Fixed: Daemon configuration manipulation via CR/LF in ISC DHCP numbered option settings #16962
DHCP (IPv6)¶
Fixed: Potential XSS in DHCPv6 Pool Descriptions #16941
DHCP Relay¶
Fixed: DHCP relay does not respect configured CARP VIP status #15017
DNS Resolver¶
Fixed: Unbound configuration may be generated with duplicate interface bindings #16906
Dashboard¶
Diagnostics¶
Dynamic DNS¶
Gateway Monitoring¶
Changed: Improve gateway status consistency #16707
Gateways¶
IPsec¶
IPv6 Router Advertisements (radvd/rtsold)¶
Fixed: IPv6 Track Interfaces ignores the
DisabledRouter Advertisements mode #16925
Interfaces¶
Logging¶
Fixed: Potential XSS via inline Firewall Log rule descriptions #16923
OpenVPN¶
Operating System¶
PPP Interfaces¶
Fixed: Potential XSS in PPP instance Provider and Plan fields #16943
Package System¶
Fixed: Error updating repository metadata at boot with certain packages installed #16784
RRD Graphs¶
Fixed: Multiple
updaterrd.shprocesses #16927
Rules / NAT¶
Fixed: Cannot add Port Forward with an unassociated filter rule #15346
Fixed: Same port forward on multiple WANs can generate a PF error due to Pure NAT mode NAT reflection #16783
Changed: Retain a copy of the failed ruleset when a filter reload fails #16796
Fixed: Potential stored XSS via Firewall Schedules #16924
Fixed: Filter rules created as part of NAT rules can have an invalid protocol value #16954
SNMP¶
System Logs¶
Changed: Exclude nginx logs from
system.log#16826
Traffic Graphs¶
Traffic Shaper (ALTQ)¶
Fixed: Traffic Shaper Wizard duplicates all firewall rules when no shaping options are enabled #16866
Wake on LAN¶
Changed: “Wake All” functionality on
services_wol.phpshould only use POST #16961
Web Interface¶
Fixed: Potential command execution via CR/LF in System Proxy settings #16898
Wireless¶
Fixed: Interfaces Status shows an invalid SSID value for Wi-Fi interfaces #16769