Core: Fixed an issue where web servers using Azure Blob Storage could reach 100% CPU with hanging requests after an application restart under concurrent load, requiring an application pool recycle to recover.
CMS: Improved security by restricting post-login redirects to trusted destinations.
Finance: Improved security by restricting access to giving transactions to authorized users.
Group: Improved security by adding permission checks before group members can be added, changed or moved.
Connection: Improved security by restricting access to person contact information to authorized users.
Communication: Improved security by ensuring subscriptions can only be made to valid communication lists, on web and mobile.
CMS: Improved security by adding validation to profile and photo updates to prevent unauthorized changes.
Core: Improved security by restricting how uploaded files are served, so they can't run scripts in the browser.
Workflow: Improved security by ensuring workflow permissions, including those inherited from categories, are consistently enforced.