GoAnywhere MFT: Release Notes | Version 7.8.0

24. April 2025
New Features
  • Added the support for legacy path-styles access to the Amazon S3 Resource.
  • Added ability to enable AES data encryption for UDP transfers made over FileCatalyst.
  • Added support for Azure Data Lake Gen2 integration as a Resource.
  • Added additional restrictions requiring Diagnostic-View persmissions to the About page.
  • Added a FileCatalyst List task for listing files on a FileCatalyst server.
  • Added File Manager logging to the Administration Audit Logs.
Enhancements
  • Enhanced messaging between GoAnywhere MFT and Gateway to avoid memory leak in rare situations.
  • Enhanced the Proejct Outline to retain the folder expand/collapse state.
  • Enhanced the process that determines if IP addresses are allowed/denied on services to be more efficient and take less memory.
  • Enabled File Restrictions by default when creating new Domains.
  • Reduced Memory Fragmentation for all service transfers.
  • Added an optional advanced backpressure system that, when enabled, reduces the memory footprint of proxied channels in GoAnywhere and mitigates the risk of channel lockup caused by backpressure issues.
  • Added option to allow Domain specific folders to be exempt from File Restrictions automatically.
  • Added Job File Auditing for the PeSit client send/receive actions.
  • Adjusted change history field for Azure resources SAS token.
Updates
  • Updated the FileCatalyst service to more efficiently utilize UDP data ports when connecting through Gateway.
  • Updated the bar chart and pie chart gadgets from Primefaces components to React components.
  • Updated the UnboundId LDAP API to the latest 4.0.14 version (addresses a memory leak).
  • Updated Tomcat from version 9.0.98 to 9.0.102.
  • Updated the mina-core library from 2.1.5 to version 2.1.1.0.
  • Updated netty-all from version 4.1.108.Final to 4.1.118.Final.
  • Updated commons-io library from version 2.1.5.1 to 2.17.0.
  • Updated JNQ from version 2.5.1 to 2.5.6.
  • Updated esapi from 2.5.3.1 to 2.6.0.0.
  • Updated Azure Blob Storage API Version from 5.5.0 to 12.23.0.
  • Upgraded PrimeFaces from 7.0.14 to 7.0.32-LTS to remediate jQuery-UI CVEs.
Updates
  • Updated the FileCatalyst service to more efficiently utilize UDP data ports when connecting through Gateway.
  • Updated the bar chart and pie chart gadgets from Primefaces components to React components.
  • Updated the UnboundId LDAP API to the latest 4.0.14 version (addresses a memory leak).
  • Updated Tomcat from version 9.0.98 to 9.0.102.
  • Updated the mina-core library from 2.1.5 to version 2.1.1.0.
  • Updated netty-all from version 4.1.108.Final to 4.1.118.Final.
  • Updated commons-io library from version 2.1.5.1 to 2.17.0.
  • Updated JNQ from version 2.5.1 to 2.5.6.
  • Updated esapi from 2.5.3.1 to 2.6.0.0.
  • Updated Azure Blob Storage API Version from 5.5.0 to 12.23.0.
  • Upgraded PrimeFaces from 7.0.14 to 7.0.32-LTS to remediate jQuery-UI CVEs.
Fixes
  • Fixed an issue where emails sent using the Files and GoDrive features in the Web Client were susceptible to cross-site scripting (XSS) attacks. This remediates CVE-2024-11922.
  • Fixed an issue with the dashboard gadgets not displaying proper text on certain Chromium builds.
  • Fixed an issue with an incorrectly labeled S3 regional server.
  • Fixed an issue wehre FCService would break if the FC Client uploaded with zip archives.
  • Fixed an issue within Job Log Purging that would leave Job Log folders locked.
  • Fixed an issue in PeSIT where the PI-27 value was incorrect for FPDU_TRANS_END when the client uses the MONO_PDU transfer type.
  • Fixed an issue with Secure Mail where the auto generated password was not being displayed to the user when „Include Password In…“ was disabled.
  • Fixed an issue where deadlocking occured when transitioning an active job to completed job.
  • Fixed an issue where directory creation in FCService could be marked as a 0 byte file.
  • Fixed an issue with AS4 processing where a security library was not initialized.
  • Fixed an issue that occured when updating a Secure Form definition where the modified by value was not getting updated.
  • Fixed an issue where adding a duplicate trigger resulted in a 500 error insteasd of displaying the appropriate duplicate trigger message.
  • Fixed an issue with an information disclosure vilnerability in SFTP error responses. When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message now shows only the virtual path instead of the absolute server path, safeguarding filesystem structure details.
  • Fixed an issue with the handling of variable names that contained leading or trailing spaces.
  • Fixed an issue within Agent Schedule where repeating scheduels jobs did not pass project variables after the initial schedule run.
  • Fixed an issue with Cloud Connector tasks having List Input Variables that could cause ClassNotFoundException if they were going to be deleted.
  • Fixed an issue with the Malicious User Name Monitor where it would flag IP Adresses if enabled but the Automatic Block List was disabled.

0 Kommentare