j5 Framework 26.0 update 10 - j5 - - Release Bulletin - Hexagon PPM

j5 Release Bulletin

PPMProduct
j5
PPMCategory_custom
Release Bulletin

Security Updates

  • 2021-03-11 - Removed calls to unsafe load functions on YAML configuration files, to prevent CVE-2017-18342 and CVE-2019-20477. (PT-6454)

  • 2021-03-16 - Removed requests_ntlm library from j5 along with ipaddress, ntlm-auth and crytography which were dependencies of requests_ntlm. (PT-6535)

  • 2021-03-16 - Upgraded Pillow from 2.9.0 to 6.2.2 in order to resolve CVE-2016-4009, CVE-2020-5311, CVE-2020-5312. (PT-6431, PT-6512)

  • 2021-04-26 - Patched Python CTypes module to prevent CVE-2021-3177. (PT-6432)

  • 2021-04-26 - Patched test for multi-byte code support to fix CVE-2020-27619. (PT-6433)

  • 2021-04-26 - Upgraded to Python 2.7.18 from Python 2.7.17. (PT-6430)

  • 2021-04-23 - Added a missing authentication check when fetching the area hierarchy. (PT-7187)

Improvements

  • 2021-05-03 - Updated properties of installers to show Hexagon ownership and sign with Hexagon certificate. (PT-4617)

Bug Fixes

  • 2021-03-19 - Clean up HTML values added in IndustraForm RichText fields before exporting to PDF. (PT-6235)

  • 2021-03-19 - Stopped attachments from temporarily disappearing when adding a non-IndustraForm entry. (PT-6210, PT-6473, PT-6474)

  • 2021-05-19 - Fixed an error exporting Logbook fields with Unicode characters into Excel. (PT-8626)

Translations

This release contains new translation strings, in the following translation domains:

  • sjsoft.Apps.Logbook (1 new strings)