GoAnywhere MFT: Release Notes | Version 7.10.0

20. April 2026
New Features
  • Added azure-identity of version 1.18.1 for Azure Entra ID support.
  • Added Flags for new/advanced settings.
  • Support Microsoft Entra ID Authentication for Azure Storage Resources.
Enhancements
  • Added „number of TCP stream“ configuration to the FileCatalyst task.
  • Added a new Flag to control the maximum allowed bytes to be read by Excel Task.
  • Added auth/api host override configuration via system properties:
    • com.fortra.inner.common.threatBrain.authHost
    • com.fortra.inner.commomn.threatBrain.apiHost
  • Added indexes to Trigger tables for improved performance.
  • Converted System Property com.fortra.sftp.server.transferGC.enabled to an Advanced Flag ‚SFTP Service Garbage Collection‘ Adjusted SFTP Service Garbage Collection Flag to trigger garbage collection on a limited basis when transfers are occuring on the SFTP Service.
  • Enhanced the Active Trigger Query to reduce query server hops improving performance.
  • Enhanced Agent Server to force remote decrypton on all Agents (Agent restart is required).
  • Enhanced the GoAnywhere Docker base image to reduce size and improve efficiency.
  • Enhanced the IAM permissions checks to be more efficient.
  • Enahnced the Mina SSH Client implementation to apply connection timeout to open subsystem for SCP/SFTP.
  • Enhanced the SFTP Server when in BC FIPS-140-3 mode to support the following key exchange algorithms:
    • diffie-hellman-group-exchange-sha256
    • diffie-hellman-group14-sha256
    • diffie-hellman-group16-sha512
    • diffie-hellman-group18-sha512
  • Enhanced the upgrade process to convert the System Property for the Excel Max Bytes Override from hot fix to an official Advanced Flag.
  • Fixed the order of closing the index wwriter, directory, and the search manager.
  • Hardened the X-Forwarded-For Filters for Admin and Web client to only resolve if trusted proxied ip and its not an IP to only resolve if trusted host Migrated Existing Admin Client X-Forwarded-For Trusted Proxy System Property to Flag and can now be managed via the UI Migrated Existing Web Client X-Forwarded-For Trusted Proxy System Property to Flag and can now be managed via the UI Added Admin Client X-Forwarded-For Trusted Hosts Flag to resolve only trusted hosts if encountered as client IP to retain backwards compatibility. Added Admin Client X-Forwarded-For Trusted Hosts Flag to resolve only trusted hosts if encountered as client IP to retain backwards compatibility.
  • Improved performance of file listing and access operations for Azure Data Lake and Azure Blog Storage.
  • SSH Resource now utilizes Mina provider by default.
  • Updated the Support Bundle to generate a new ‚Flags‘ report to provide the flag overrides by the admin user.
Fixes
  • Fix missing Premain-Class in minimal upgrader jay in gamft-upgrader Fix executable permissions for mft_base_legacy shell scripts.
  • Fixed an issue preventing importing of SSH Keys into KMS after SFTP server startup in FIPS-140-3 Mode.
  • Fixed an issue preventing the import and usage of some ECDSA SSH Public or Private key types when in FIPs mode.
  • Fixed an issue that would prevent a web user from being disabled after too many invalid SSH Key Attempts.
  • Fixed an issue using Mina SSH Client during listings and downloads would miscalculate the bytes to allocate causing failure.
  • Fixed an issue when an Agent message was received after the timeout causing the control channel to close.
  • Improved the message handling within the Asynchronous messaging to fail fast.
  • Fixed an issue when viewing web users where group consolidation was missing.
  • Fixed an issue where a 500 error could be thrown when trying to validate an online license from the License page.
  • Fixed an issue where agent projects that are large in payload could cause project xml corruption when in a cluster.
  • Fixed an issue where clicking the Submit button on the two factor authentication screen for the Admin Client would cause a 500 error.
  • Fixed an issue where File Buffer Size was not respected when reading files within Encrypted Folder feature.
  • Fixed an issue where Force IDP Authentication was not respected for certain race conditions.
  • Fixed an issue where setting a specificTLS protocol on FileCatalyst Service would cause FileCatalyst tasks to break without other configurations.
  • Fixed an issue where the PeSIT Server would periodically get 299 errors when receiving a file.
  • Fixed an issue where the upgrader could fail when trying to delete the index IDX_DPA_ACTIVE_JOB.
  • Fixed an issue with LDAP Managed Login Methods configured with SSL would have strict host name failures due to missing host name on the socket.
  • Fixed an issue with Master Encryption Key aliases not being loaded as lowercase on first decrypt.
  • Fixed an issue with the AS4 Push Task where Source File(s) would not be sent when using certificate authentication.
  • Fixed an issue with the MINA SSH Client that would leak threads.
  • Increased the performance speed for uploads/downloads using MINA SSH Client.
  • Fixed issue where for loops in FileCatalyst task would add extra log handlers for each iteration of the loop.
  • Fixed issue where non-transfer-transactions within FCService would show up as transfers in the „Active Transfers“ UI.
  • Fixed issue where one broken virtual folder/file would cause full listings to break in FileCatalyst Service.
  • Fixed issue where transfer rates for Services weren’t properly displaying the average rate over time.
  • Fixing the issue where remote file pickers within the FileCatalyst Service were using the wrong validation method.
  • Improved email template sanitization to block unsafe injected HTML/script content in generated emails without breaking supported formatting.
  • Removed Base64 Encoded EICAR test string.
  • Removed default SFTP Service DSAA key from new instlalations.
  • Removed spaces from Syslog Message Id values for Structured Data to conform to RFC5424.
  • Added escaping for Syslog Structured Message Parameters to conform to RFC5424.
  • Resolves issue with AS4 Push body XML parsing.
  • Turn off BC native support to avoid permission issue on Unix systems.
  • Updated FTP/FTPS/SFTP Put tasks to only refresh remote properties when output destination variables are being used.
  • Updated the captcha verification to occur prior to any backend validation.
Updates
  • Updated AWS SDK from V1 to V2
  • Updated JNQ from version 2.5.6 to 2.7.1.
  • Updated netty from version 4.1.128.Final to 4.2.12.Final
  • Updated nimbus-jose-jwt library from version 9.48 to 10.0.2
  • Updated Tomcat from version 9.0.111 to 9.0.117.
  • Upgrade eslint from 9.39.2 to 9.39.3
  • Upgrade log5j-2.24.3 to log5j-2.25.4
  • Upgrade Lucene API from 4.7.2 to 9.12.3
  • Upgraded mssql-jdbc from 12.8.0.jre11 to 12.8.2.jre11
  • Upgraded reactor-netty-http from version 1.0.48 to version 1.2.14

0 Kommentare