Skip to content

OpenRemote

v1.27.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

asset-management building web dataplatform device-management edge-computing
+14 more
energy energy-management energy-monitor fleet-management fleet-telematics iot iot-application iot-platform modbus mqtt mqtt-broker ota-update rules-engine smartcity

Affected surfaces

rbac

Summary

AI summary

Updates Other changes, fix, and πŸ”’ Security updates across a mixed release.

Full changelog

⚠️ Important notes / Before you upgrade ⚠️

  • The Energy- related source code, together with the Demo setup, have been moved to separate extension artifacts.
    These artifacts are still included in the openremote/openremote Docker image, therefore no breaking changes are introduced.
    Users can now install and build their own extensions; read more about this on our documentation website.

  • Deprecation warning for custom projects: using openremoteVersion in gradle.properties is now deprecated,
    and a warning is sent when used. Instead, users should set the openremote version in the gradle/libs.versions.toml file.

What's Changed

πŸ”’ Security updates

  • (CVE pending) on Cross-tenant IDOR in setAssetLinks allows cross-realm alarm-asset link persistence via validation bypass

⭐ Enhancements

  • Improve Gradle plugin and dependency version catalog configuration by @wborn in https://github.com/openremote/openremote/pull/3058

🐞 Bug fixes

  • Fix services migration in development when the keystore file is missing by @Ekhorn in https://github.com/openremote/openremote/pull/3044

Other changes

  • [Extensions] Remove Energy and Demo Setup extensions by @denniskuijs in https://github.com/openremote/openremote/pull/3008
  • [CI/CD] Add CI/CD workflow for extensions by @denniskuijs in https://github.com/openremote/openremote/pull/3007
  • Fix staging workflow issue by @denniskuijs in https://github.com/openremote/openremote/pull/3036
  • Bump websocket-driver from 0.7.4 to 0.7.5 by @dependabot[bot] in https://github.com/openremote/openremote/pull/3040
  • Bump groovy from 5.0.6 to 5.0.7 by @dependabot[bot] in https://github.com/openremote/openremote/pull/3029
  • Remove energy assets and duplicate tests from asset.test.ts by @Ekhorn in https://github.com/openremote/openremote/pull/3048
  • Fix issues with Extensions CI/CD by @denniskuijs in https://github.com/openremote/openremote/pull/3046
  • Fix Gradle deprecations by @wborn in https://github.com/openremote/openremote/pull/3043
  • fix: Add missing permissions to extensions CI/CD workflow by @denniskuijs in https://github.com/openremote/openremote/pull/3049
  • fix: extensions CI/CD uses wrong GH token by @denniskuijs in https://github.com/openremote/openremote/pull/3050
  • fix: Change extensions workflow parameter names to lowerCase by @denniskuijs in https://github.com/openremote/openremote/pull/3052
  • Bump the vaadin group across 1 directory with 22 updates by @dependabot[bot] in https://github.com/openremote/openremote/pull/3038
  • fix: Extensions CI/CD issues by @denniskuijs in https://github.com/openremote/openremote/pull/3059
  • Update Process CI/CD JSON GitHub Action SHA by @denniskuijs in https://github.com/openremote/openremote/pull/3062
  • Bump actions/setup-java from 5.5.0 to 5.6.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/3055
  • Bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.1 by @dependabot[bot] in https://github.com/openremote/openremote/pull/3054
  • Read OpenRemote version from Gradle version catalog by @wborn in https://github.com/openremote/openremote/pull/3065
  • Bump openremote/openremote/.github/actions/process-cicd-json from 3125aa44c8977c7a373bd22a3c4dd0ccb56ca44c to f667c603a447af79dda980f1dd1d734fd4679b2e by @dependabot[bot] in https://github.com/openremote/openremote/pull/3067
  • fix: CI/CD Deployment issue with extensions by @denniskuijs in https://github.com/openremote/openremote/pull/3069
  • fix: Release issue with demo-setup by @denniskuijs in https://github.com/openremote/openremote/pull/3076

Full Changelog: https://github.com/openremote/openremote/compare/1.26.2...1.27.0

Breaking Changes

  • Removal of `openremoteVersion` in `gradle.properties`; use version catalog instead.

Security Fixes

  • (CVE pending) Fix cross‑tenant IDOR in `setAssetLinks` that allowed persistence of alarm‑asset links across realms via validation bypass.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track OpenRemote

Get notified when new releases ship.

Sign up free

About OpenRemote

IoT Asset management, Flow Rules and WHEN-THEN rules, Data visualization, Edge Gateway.

All releases β†’

Related context

Earlier breaking changes

  • v1.24.0 Requires PostgreSQL versions 15.14+ or 17.9+; older versions will fail to boot.
  • v1.24.0 PostgreSQL TimescaleDB now uses HyperCore compression by default.
  • v1.24.0 Upgraded to Groovy version 5.0, impacting Groovy rules and tests.
  • v1.24.0 Replace obsolete Keycloak adapter with Nimbus based JWT token verifier.

Beta — feedback welcome: [email protected]