Skip to content

Omeka S

v4.2.1 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

cms linked-data php

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates Bugs Fixed, For Developers, and Server Support across a mixed release.

Full changelog

Server Support

  • PHP 8.5 is now supported

Bugs Fixed

  • Block titles for the IIIF page blocks were not properly escaped
  • The IIIF presentation page block did not respect the site's configured IIIF viewer setting for the Mirador theme
  • Some fields were not aligned properly on the admin advanced search
  • Themes could not use the Ckeditor form elements to allow HTML input for theme settings
  • Unnecessary spacing when listing data types in resource template browse
  • Modules using older code for database queries could encounter errors related to core events like those used for processing fulltext search
  • The Asset add form only allowed a fixed list of file types regardless of what types were specified in config
  • The confirm password check did not properly run when the confirm box was left blank
  • Navigation allowed script-executing javascript: URLs for custom pages (reported by Frank Mancia)
  • Cross-site search could include results for sites the current user did not have permission to view
  • Mirador annotations displayed with incorrectly thick borders
  • Vocabulary prefixes were not correctly checked against the set of allowed characters when creating the vocabulary
  • Uploaded "audio/mpeg" files with no extension used the unlikely ".mpga" extension instead of the more-likely ".mp3"
  • Fulltext search improperly saved some characters as HTML entities when HTML Purifier was disabled, preventing the search from properly returning them
  • The has_media=1 query could improperly reveal the existence of private media
  • The advanced search "Sort by" input was not properly set by the current query
  • Purely-numeric items in filtered sidebar selectors caused a JS error
  • The List of pages block rendered incorrect HTML for its nested lists
  • Fixed PHP 8.5 deprecations

Improvements

  • Accessibility improvements
    • Removed default placeholder text for the basic public search that did not have enough room to render on some themes
    • Admin form fieldsets now use headings in addition to legends for group labels
    • Applied aria-expanded attribute to expanding/collapsing elements
    • Increased target size for expand/collapse controls
    • The default "Welcome" page no longer includes a "subtitle" style that has low contrast
    • Assets now use their alt when showing a just-selected asset in a form
  • Batch edit now allows setting resource custom thumbnails
  • Improved performance for browse pages by avoiding unnecessary queries related to getting the primary media for resources
  • Improved performance for queries that sort by the count of a related entity

For Developers

  • New config helper for getting merged config in a view
  • api helper now allows passing request options to API
  • The IIIF page blocks now use partials when rendering
  • The Laminas config, loader, log, mail, mime, and mvc packages now use forks maintained by the Omeka Team
  • Core usage of the laminas-math and laminas-dom extensions is removed

Security Fixes

  • Navigation validation prevents script‑executing `javascript:` URLs
  • `has_media=1` query no longer reveals private media existence

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Omeka S

Get notified when new releases ship.

Sign up free

About Omeka S

Next-generation web publishing platform for institutions interested in connecting digital cultural heritage collections with other resources online.

All releases →

Related context

Beta — feedback welcome: [email protected]