Wiki

Scale Your Enterprise

User Tools

Site Tools

mbstring extension must be loaded in order to run mPDF

versago:release_notes

This is an old revision of the document!


Versago Release Notes

Version - 2.5, Build 2.5.7

Release notes are cumulative for all builds of v2.5

  • New Features
    • VGO-2171 - Autocomplete has been disabled in password elements. However, the setting may be ignored by the browser.
  • Improvements
    • VGO-2128 - Improved authentication security by removing unnecessary functions from asmx and web API controllers.
    • VGO-2172 - Implemented security headers for improved security. The URL Rewrite extension for IIS must be installed. It can be downloaded from https://www.iis.net/downloads/microsoft/url-rewrite.
    • VGO-2173 - A vulnerability was addressed were passwords were stored in the password history table in plain text.
    • VGO-2300 - Addressed an issue where a resource Forbidden message was displayed even though the user credentials were correct.
  • Bug Fixes
    • VGO-2146 - Addressed a vulnerability where an attacker might bypass authentication.
    • VGO-2148 - Address a vulnerability where information was disclosed in the form of API documentation.
    • VGO-2149 - Addressed a vulnerability where access rights at the function level have been verified.
    • VGO-2150 - Addressed a vulnerability to remote code execution (RCE).
    • VGO-2151 - Addressed a vulnerability to SQL injection attacks originating from input verification.
    • VGO-2152 - Addressed CSRF vulnerability.
    • VGO-2153 - Addressed a vulnerability where the application allowed the upload of an SVG file containing HTML content.
    • VGO-2154 - Addressed a vulnerability where references to internal objects were not secure.
    • VGO-2155 - Addressed a vulnerability denominated Persistent XSS attack where an injected script is permanently stored on the target servers, such as in a database, in a message forum, visitor log, comment field, etc.
    • VGO-2156 - Addressed a vulnerability where some sensitive data was exposed to attack.
    • VGO-2157 - Addressed a vulnerability where attacks aim at discovering non-public web services by retrieving their WSDL files.
    • VGO-2159 - Addressed a vulnerability where by using old session cookies, user profiles can be accessed.
    • VGO-2176 - HTTP is no longer permitted. HTTPS must be deployed with a valid certificate.
    • VGO-2177 - The session timeout setting for end-users and administrators have been merged. There is only one setting across the site.
    • VGO-2182 - Some ad blocker extensions to the browser may cause problems with the Admin Console. Please disable any extensions that block the Versago site.
    • VGO-2185 - Addressed an issue where the password field for a new user was not large enough. Expanded to max 32 characters. See https://wiki.twbs.com/doku.php/versago/role_profile_user_configuration#user_details_core_information for more information.
    • VGO-2192 - Addressed a vulnerability where several HTTP methods designed to aid developers in deploying and testing applications were allowed.
    • VGO-2195 - Addressed a vulnerability where a Referrer-Policy was not being used.
    • VGO-2196 - Addressed a vulnerability where HTML comments were exposed.
    • VGO-2220 - Addressed an issue with reports that allow record submission where the field's length created to store the submission was limited to 50 characters.
    • VGO-2221 - Addressed an issue where action links to an https site were not working properly.
    • VGO-2235 - Mask passwords will no longer be displayed in pages where there is a password field such as DB connections and Email settings. If the password needs to be changed, the Update Password button must be clicked first in order to enable the field.
    • VGO-2240 - Address an issue where action links did not export correctly. If a form contained multiple action links and it was imported and exported, all links would point to the same link in the new environment.
    • VGO-2247 - Addresses an issue where images in Crystal Reports were not displayed.
    • VGO-2296 - Addressed an issue where system session time out did not follow the set value.
versago/release_notes.1643219120.txt.gz · Last modified: 2022/01/26 12:45 by dlee