This release includes 1 security fix for security teams reviewing exposed deployments.
Published 19d
Communication & Email
✓ No known CVEs patched
This release patches 1 known CVE
Topics
collaboration
jabber
java
openfire
xmpp
xmpp-server
Affected surfaces
auth
rbac
rce_ssrf
deps
Summary
AI summaryFixes a NullPointerException in OfflineMessageStore and multiple PubSub subscription consistency issues.
Full changelog
Improvement
- [OF-3300] - Improve handling of unexpected errors in MultiUserChatServiceImpl
- [OF-3304] - MUCPersistenceManager MUC history reload limit set to X log message is unhelpful
- [OF-3310] - Inconsistent duplicate-subscription policy for 'nodes' vs 'items' subscription types on collection nodes when multi-subscribe is enabled
- [OF-3312] - Replace string identity comparison when setting currentKey
- [OF-3317] - Log encryption property migration in audit log
- [OF-3333] - Upgrade Netty from 4.2.13.Final to 4.2.16.Final
Bug
- [OF-3301] - NullPointerException in OfflineMessageStore.getSize() due to unsafe cache access
- [OF-3305] - Unable to save XML properties during PBKDF2 migration
- [OF-3306] - Excessive memory consumption caused by bloated ofPubsubSubscription table
- [OF-3307] - PubSub subscriptions are incorrectly treated as unique per owner instead of per subscription JID
- [OF-3309] - Duplicate 'nodes'-type subscription to a collection node returns instead of current subscription state when multi-subscribe is disabled
- [OF-3311] - nodeMeetsPreconditions() ignores extra precondition values when the node configuration has only one value
- [OF-3314] - Harden null-handling and cache access in FaviconServlet
- [OF-3315] - Re-validate redirect targets to close residual SSRF in FaviconServlet
- [OF-3316] - Improve favicon caching behavior and response semantics
- [OF-3318] - SessionManager teardown ownership
- [OF-3319] - IQBindHandler busy-waits up to 20s on resource conflict, causing thread starvation and not working in a cluster
- [OF-3321] - ConcurrentModificationException while initializing outbound S2S
- [OF-3324] - IP addresses are encoded as dNSName instead of iPAddress in certificate SANs
- [OF-3325] - CI doesn't publish Docker images for tags
- [OF-3331] - Guard head-side pipeline handlers against duplicate channelActive execution after TLS handshake
- [OF-3332] - Outbound S2S DirectTLS connection fails with NullPointerException in NettyConnection.startTLS
sha256sum values
dc887032619b7ecf66cc8c17dc5cedc13c2479525cd93b41e5d999e4ec942adf openfire-5.1.1-1.noarch.rpm
4f6c5ccfe44fdd494760ae5a6f00f971ea000ec6c69e1481d3546bed994598e2 openfire_5.1.1_all.deb
17eafa2641a5cbe226328d54e115fd1780a90d6fedb6d63d8bcea048f91f23ab openfire_5_1_1.dmg
68b69309f22435e4996b18b21a451d8c3b98a543aa8680436694bf4a235b8299 openfire_5_1_1.exe
d930be11c93c995ee0a045118d0539629bd27d983ad99e6f174ded6453612a0d openfire_5_1_1.tar.gz
b55659388274deedde92813ed830e1060c89b48fc3d61e6227c153bd4d96b57e openfire_5_1_1_x64.exe
9faa8900c8aa56822deb83c82339842794b6e2e58be61ca08dbdf948ee931cd6 openfire_5_1_1.zip
Security Fixes
- Re-validate redirect targets to close residual SSRF in FaviconServlet
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]