v18.5 Release Notes

  • Core: Fixed an issue where web servers using Azure Blob Storage could reach 100% CPU with hanging requests after an application restart under concurrent load, requiring an application pool recycle to recover.

  • CMS: Improved security by restricting post-login redirects to trusted destinations.

  • Finance: Improved security by restricting access to giving transactions to authorized users.

  • Group: Improved security by adding permission checks before group members can be added, changed or moved.

  • Connection: Improved security by restricting access to person contact information to authorized users.

  • Communication: Improved security by ensuring subscriptions can only be made to valid communication lists, on web and mobile.

  • CMS: Improved security by adding validation to profile and photo updates to prevent unauthorized changes.

  • Core: Improved security by restricting how uploaded files are served, so they can't run scripts in the browser.

  • Workflow: Improved security by ensuring workflow permissions, including those inherited from categories, are consistently enforced.