Verj.io V5.12.0 released

Check for important Verj.io announcements such as version, service packs and patch releases, event dates, etc

Moderators: Jon, Steve, Ian, civanderputt, Dave

Steve
Moderator
Moderator
Posts: 414
Joined: Fri Sep 07, 2007 3:44 pm
Location: Sandy, UK
Contact:

Verj.io V5.12.0 released

#1

Postby Steve » Wed Jan 04, 2023 2:49 pm

Verj.io V5.12.0 is now available and can be downloaded using the links below.

Downloads:
Verj.io Studio Links:
Windows 64 bit: https://downloads.verj.io/verjio/v5.12. ... _win64.exe
Linux 64 bit: https://downloads.verj.io/verjio/v5.12. ... x64.tar.gz
Mac: https://downloads.verj.io/verjio/v5.12. ... _0_mac.dmg

On-premise Server Links
Windows 64 bit: https://downloads.verj.io/verjio/v5.12. ... _win64.exe
Linux 64 bit: https://downloads.verj.io/verjio/v5.12. ... x64.tar.gz


Changes introduced in Version 5.12.0:
  1. The introduction of three Media Controls:
    • Audio Control – used to embed audio content onto a page.

    • Video Control – used to embed video content onto a page.

    • IFrame Control – used to embed HTML content into the current page.

  2. Upgraded to support Java 17.

  3. JavaScript API documentation included with the Verj.io reference documentation. This is accessible from the Verj.io Studio Help menu.

Security Fixes in V5.12.0:
  1. Upgrade to tomcat 9.0.69 that fixes:
    • CVE-2022-34305 - The Form authentication example in the examples web application displayed user provided data without filtering, exposing an XSS vulnerability.

    • CVE-2022-42252 - If Tomcat was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (not the default), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.


  2. Commons Texts updated to 1.10.0 that fixes:
    • CVE-2022-42889 - Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded.

  3. Configure X-Frame-Options HTTP response header to indicate whether or not a browser should be allowed to render a Frame, IFrame, Embed or Object HTML elements.

  4. Verj.io Service Plans and On-Premises environments can restrict access to known Verj.io Studios by configuring a Whitelist in their respective Administration Applications. This Whitelist replaces the Whitelist previously used to restrict deployment.

  5. Upgrade Apache HTTP Client 4.5.12 to HTTP Client 5.2.

Release notes and installation instructions:
See the V5.12.0 Readme
0 x

Who is online

Users browsing this forum: No registered users and 49 guests