Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Published by Scroll Versions from space IPP and version 9.5

This section lists bugs that are resolved in this release.

Referenced PR ID

Description

INST-7486Security: Microsoft ASP.NET MS-DOS Device Name
possible DoS attack vector (Port 80 & 443)
INST-8488Security: User activity auditing capability
INST-10841Compare view displays revisions incorrectly in full screen mode
INST-12117Security: Session Token in URL
, found during penetration test
INST-12118Security: Session cookie
not
set with the Secure flag
INST-12907Preview - Approve All button is greyed out when redeeming Secure Link for selected pages
INST-13189Show "Work in Progress" in page UI
INST-13211Failed uploads missing in job history
INST-13223Security:
Implement reCAPTCHA to protect against Email Spamming
reCAPTCHA implementation
INST-13258Managed Services: Set Application Pools to AlwaysRunning
INST-13400
Security:
Adding users through spreadsheet allows them login without password change
INST-13504Icons for Approval Not Requested and Waiting for Corrections
INST-13523Security: Path-relative stylesheet import (PRSSI) vulnerability
INST-13534Security: HTML5 Local storage
is
enabled
INST
-13608Security: CSP: Wildcard Directive, CSP: style-src unsafe-inline, and Absence of Anti-CSRF Tokens
-13578Pressproof - improved memory performance
INST-13590PressProof - Surface renders when not supposed to, but doesn't rewrite surface PNG file
INST-13594Cookie notification at login page
INST-13608Security: Other vulnerabilities
INST-13617Security:
IPP should be protected from
Zero day log4j vulnerability
INST-13621RBA: Create User action completes but not creating a user
INST-13637Security: HTTP header information
disclosure.
INST-13638Security: Confirmation email not sent on user password change
INST-13639Security: Sensitive data
is
cached
locally
INST-13640Security: Cookie missing HTTPOnly flag
INST-13641Security: Host header injection vulnerability
INST-13642Security: Email bombing
is possible with InSite
INST-13645Security: Passwords
are emailed
in plain text
INST-
10841
13651
HTML5 Smart Review : Compare view display revisions incorrectly in full screen mode.INST-12907Preview - Approve All button is greyed out when redeeming Secure Link for selected pagesINST-13258Managed Services: The IPP installer and/or ICU should change all Application Pools to AlwaysRunning from OnDemandINST-13578Pressproof - Better memory performance needed
Security: Block uploads of a webshell and execute “tasklist”
INST-13667Reword 'Delete Job' right to 'Delete Job (Staff User only)'
INST-13590PressProof - Surface renders when not supposed to, but doesn't rewrite surface PNG file
INST-13673Page selection acts
odd
wrong when sorted by Position
-- for job with multi page set
INST-13689
500 internal server error when open
Server error on administration page after satellite join to enterprise.