github Keeper-Security/Commander v18.1.7
Release 18.1.7

4 hours ago

Security

  • KC-1471: Prevent newline injection in connect command prompts. Control characters are now escaped and shell comments handled, closing a path where an operator with Can Edit on a shared record could hide commands in a confirmation prompt and exfiltrate device credentials without being noticed.
  • KC-1462: Validate record ownership in the audit-log command. Only operator-owned records are now eligible as an export destination, preventing an attacker from hijacking an export by sharing a malicious record with a matching title. Also removes TLS verification bypass from Splunk exports.

Features

  • KC-1442: Add Classic-to-NSF conversion command, with negative-flow tests and support for skipping records that are already nested-share.
  • DR-1324: Generate and deliver tokens.

Improvements

  • KC-1461: Limit NSF folder depth on import, with a sibling-flatten fallback and a structure report when limits are exceeded.
  • Improve LoadRecordTypes command: continues past invalid custom record types instead of aborting, with more verbose and color-coded logging.
  • Add filtering while printing inherited and denied-access permissions for folders and records.

Fixes

  • Fix folder properties mutation bug in the NSF share-folder command.
  • Fix service mode response status.
  • Fix SaaS field check incorrectly flagging non-required blank values.

Don't miss a new Commander release

NewReleases is sending notifications on new releases.