This section lists bugs that are resolved in this release.
Referenced PR ID | Description |
---|---|
INST-7486 | Security: Microsoft ASP.NET MS-DOS Device Name |
INST-8488 | Security: User activity auditing capability |
INST-10841 | Compare view displays revisions incorrectly in full screen mode |
INST-12117 | Security: Session Token in URL |
INST-12118 | Security: Session cookie set with the Secure flag |
INST-12907 | Preview - Approve All button is greyed out when redeeming Secure Link for selected pages |
INST-13211 | Failed uploads missing in job history |
INST-13223 | Security: reCAPTCHA implementation |
INST-13258 | Managed Services: Set Application Pools to AlwaysRunning |
INST-13400 | Security: Adding users through spreadsheet allows them login without password change |
INST-13523 | Security: Path-relative stylesheet import (PRSSI) vulnerability |
INST-13534 | Security: HTML5 Local storage enabled |
INST-13578 | Pressproof - improved memory performance |
INST-13590 | PressProof - Surface renders when not supposed to, but doesn't rewrite surface PNG file |
INST-13608 | Security: CSP: Wildcard Directive, CSP: style-src unsafe-inline, and Absence of Anti-CSRF Tokens issues |
INST-13617 | Security: Zero day log4j vulnerability |
INST-13621 | RBA: Create User action completes but not creating a user |
INST-13637 | Security: HTTP header information |
INST-13638 | Security: Confirmation email not sent on user password change |
INST-13639 | Security: Sensitive data cached |
INST-13640 | Security: Cookie missing HTTPOnly flag |
INST-13641 | Security: Host header injection vulnerability |
INST-13642 | Security: Email bombing |
INST-13645 | Security: Passwords in plain text |
INST-13651 | Security: Block uploads of a webshell and execute “tasklist” |
INST-13673 | Page selection acts wrong when sorted by Position |
INST-13689 | Server error on administration page after satellite join to enterprise. |