Skip to content

Openfire

v5.1.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 19d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

collaboration jabber java openfire xmpp xmpp-server

Affected surfaces

auth rbac rce_ssrf deps

Summary

AI summary

Fixes a NullPointerException in OfflineMessageStore and multiple PubSub subscription consistency issues.

Full changelog

Improvement

  • [OF-3300] - Improve handling of unexpected errors in MultiUserChatServiceImpl
  • [OF-3304] - MUCPersistenceManager MUC history reload limit set to X log message is unhelpful
  • [OF-3310] - Inconsistent duplicate-subscription policy for 'nodes' vs 'items' subscription types on collection nodes when multi-subscribe is enabled
  • [OF-3312] - Replace string identity comparison when setting currentKey
  • [OF-3317] - Log encryption property migration in audit log
  • [OF-3333] - Upgrade Netty from 4.2.13.Final to 4.2.16.Final

Bug

  • [OF-3301] - NullPointerException in OfflineMessageStore.getSize() due to unsafe cache access
  • [OF-3305] - Unable to save XML properties during PBKDF2 migration
  • [OF-3306] - Excessive memory consumption caused by bloated ofPubsubSubscription table
  • [OF-3307] - PubSub subscriptions are incorrectly treated as unique per owner instead of per subscription JID
  • [OF-3309] - Duplicate 'nodes'-type subscription to a collection node returns instead of current subscription state when multi-subscribe is disabled
  • [OF-3311] - nodeMeetsPreconditions() ignores extra precondition values when the node configuration has only one value
  • [OF-3314] - Harden null-handling and cache access in FaviconServlet
  • [OF-3315] - Re-validate redirect targets to close residual SSRF in FaviconServlet
  • [OF-3316] - Improve favicon caching behavior and response semantics
  • [OF-3318] - SessionManager teardown ownership
  • [OF-3319] - IQBindHandler busy-waits up to 20s on resource conflict, causing thread starvation and not working in a cluster
  • [OF-3321] - ConcurrentModificationException while initializing outbound S2S
  • [OF-3324] - IP addresses are encoded as dNSName instead of iPAddress in certificate SANs
  • [OF-3325] - CI doesn't publish Docker images for tags
  • [OF-3331] - Guard head-side pipeline handlers against duplicate channelActive execution after TLS handshake
  • [OF-3332] - Outbound S2S DirectTLS connection fails with NullPointerException in NettyConnection.startTLS

sha256sum values

dc887032619b7ecf66cc8c17dc5cedc13c2479525cd93b41e5d999e4ec942adf  openfire-5.1.1-1.noarch.rpm
4f6c5ccfe44fdd494760ae5a6f00f971ea000ec6c69e1481d3546bed994598e2  openfire_5.1.1_all.deb
17eafa2641a5cbe226328d54e115fd1780a90d6fedb6d63d8bcea048f91f23ab  openfire_5_1_1.dmg
68b69309f22435e4996b18b21a451d8c3b98a543aa8680436694bf4a235b8299  openfire_5_1_1.exe
d930be11c93c995ee0a045118d0539629bd27d983ad99e6f174ded6453612a0d  openfire_5_1_1.tar.gz
b55659388274deedde92813ed830e1060c89b48fc3d61e6227c153bd4d96b57e  openfire_5_1_1_x64.exe
9faa8900c8aa56822deb83c82339842794b6e2e58be61ca08dbdf948ee931cd6  openfire_5_1_1.zip

Security Fixes

  • Re-validate redirect targets to close residual SSRF in FaviconServlet

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Openfire

Get notified when new releases ship.

Sign up free

About Openfire

Real time collaboration (RTC) server.

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]