Openfire 4.7.5 Release
4.7.5 -- May 23, 2023
Improvement
- [OF-2459] - Admin console CSS tweaks
- [OF-2461] - Validate JIDs that are sent by remote servers
- [OF-2462] - Apply nodeprep on S2S stanza addresses
- [OF-2464] - Do not default to Chinese locale
- [OF-2539] - Name threads
- [OF-2541] - Plugins should have updated SCM references
Task
- [OF-2508] - Ensure that MUC Room names are nodeprepped
- [OF-2584] - Update dependency-check to 8.1.2
- [OF-2585] - Update commons-fileupload to 1.5
- [OF-2586] - Update mysql-connector from 8.0.28 to 8.0.32
- [OF-2587] - Update twelvemonkeys imageio-core from 3.5 to 3.7.1 or higher
- [OF-2588] - Update SQL Server JDBC driver from 7.4.1 to 9.4.1
- [OF-2589] - Remove protobuf-java from mysql-connector-j
Story
- [OF-2493] - Update postgresql to 42.4.1
Sub-task
- [OF-2596] - Improve detection of path traversal
- [OF-2597] - Add config option for using wildcards in AuthCheckFilter
- [OF-2598] - Remove wildcard usage in AuthCheckFilter
- [OF-2599] - Avoid having setup-specific auth-excludes after install
Bug
- [OF-2538] - Overzealous deletion of child properties
- [OF-2543] - pubsub should always deliver payloads when items are retrieved.
- [OF-2561] - Fallback of verifyCertificateValidity for connection listener uses incorrect setting
- [OF-2575] - Text formatting error in registration settings
- [OF-2578] - Fix failing aioxmpp tests
- [OF-2595] - CVE-2023-32315 Admin Console Auth Bypass
sha256sum
values
f70faf11b4798fefb26a20f7d60288d275a6d568db78faf79a4194cbae72eab4 openfire-4.7.5-1.noarch.rpm
d1283d417dacb74d67334c06420679aae62d088bd3439c8135ccfc272fd5b95b openfire_4.7.5_all.deb
60d8efb96a1891cda2deac2cda9808cf6adec259f090d3a7fb2b7ca21484d75b openfire_4_7_5.exe
98d36c2318706c545345274234e2f5ccbf0f72f7801133effea342e2776b8bb0 openfire_4_7_5.tar.gz
e95348be890aff64a7447295ab18eebb29db4bdc346b802df0c878ebbbf1d18e openfire_4_7_5_x64.exe
a5bb8c9b944b915bdf7ecf92cd2a689d0cf09e88bfc2df960f38000f6b788194 openfire_4_7_5.zip