This release includes 5 security fixes for security teams reviewing exposed deployments.
Published 1mo
Data Warehouses & Analytics
✓ No known CVEs patched
This release patches 5 known CVEs
Topics
cdp
cms
cms-framework
customer-data-platform
dam
data-management
+13 more
digital-platform
ecommerce
ecommerce-platform
experience-manager
master-data-management
mdm
online-shop
pim
pimcore
product-information-management
product-management
shop
wcms
Affected surfaces
auth
rbac
rce_ssrf
Summary
AI summaryUpdates Fix, NumericRange/DateRange/Geopoint/Geobounds, and fix across a mixed release.
Full changelog
What's Changed
- [Security]: Improve unserialize security in Hotspot Image by @kingjia90 in https://github.com/pimcore/pimcore/pull/19181
- [Security] Deserialization of Untrusted Data in pimcore/pimcore by @robertSt7 in https://github.com/pimcore/pimcore/pull/19167
- [Security] Harden field name validation by @mcop1 in https://github.com/pimcore/pimcore/pull/19183
- [Security]: Improve sql concatenation in Custom Reports by @kingjia90 in https://github.com/pimcore/pimcore/pull/19175
- Error “Failed to open stream: Too many open files” occurs during long-running processes involving asset operations by @robertSt7 in https://github.com/pimcore/pimcore/pull/19129
- [Document Editor] Deprecate editable dialog width/height configuration options by @lukmzig in https://github.com/pimcore/pimcore/pull/19187
- [Security] Restrict allowed classes when unserializing the admin session token by @mcop1 in https://github.com/pimcore/pimcore/pull/19191
- [Bug, EC] PEES-989: MimeType gets guessed wrong by @robertSt7 in https://github.com/pimcore/pimcore/pull/19186
- [Task] Fix broken markdown link in admin session token allowed-classes doc by @mcop1 in https://github.com/pimcore/pimcore/pull/19192
- Fix: add method and property check to twig SecurityPolicy by @robertSt7 in https://github.com/pimcore/pimcore/pull/19193
- Snippets will be cached with wrong links in preview view by @blankse in https://github.com/pimcore/pimcore/pull/18808
- [Bugfix] Composite data types drop values when a sub-value is empty (NumericRange/DateRange/Geopoint/Geobounds) #18144 by @mcop1 in https://github.com/pimcore/pimcore/pull/19197
- fix: Listing::getTotalCount() should use connected parameters by @youwe-petervanderwal in https://github.com/pimcore/pimcore/pull/18907
- [Bug][Asset Preview] Fallback for SVGs that cannot be converted by @kingjia90 in https://github.com/pimcore/pimcore/pull/19184
- Docs: Add MimeType Event by @robertSt7 in https://github.com/pimcore/pimcore/pull/19200
- [Bug] Fix SVG/vector transparent background rendered as black by @kingjia90 in https://github.com/pimcore/pimcore/pull/19201
- [Bug]: pimcoreblock inside pimcoremanualblock does not work with new syntax by @robertSt7 in https://github.com/pimcore/pimcore/pull/19196
- [Bug] Fix Video editable rendering states in Studio by @markus-moser in https://github.com/pimcore/pimcore/pull/19106
- Allow restricting subtypes and classes in link edit panel by @jdreesen in https://github.com/pimcore/pimcore/pull/18840
- [Bug]: Fix Content from document with assigned content-main document by @kingjia90 in https://github.com/pimcore/pimcore/pull/19209
- [Bug][Documents][Renderlets] Streamline passing of config attributes to renderlets by @robertSt7 in https://github.com/pimcore/pimcore/pull/19212
- Remove broken and unnecessary transaction handling from
NotificationServiceby @jdreesen in https://github.com/pimcore/pimcore/pull/19207 - skip checking pdf after it has been checked and marked safe. by @cancan101 in https://github.com/pimcore/pimcore/pull/18541
- [Bug]: performance problem when copying object to folder with many children objects by @robertSt7 in https://github.com/pimcore/pimcore/pull/19205
- Fix typo in the docs by @jdreesen in https://github.com/pimcore/pimcore/pull/18951
- Remove service definition for non-existing service by @pimcoreneusta in https://github.com/pimcore/pimcore/pull/19100
- Fix Pimcore version in the docs by @jdreesen in https://github.com/pimcore/pimcore/pull/18950
- Fix null argument exception in tree by @wwnorden in https://github.com/pimcore/pimcore/pull/19111
- [Bug] Fix TypeError in for empty link localization (#19165] by @simonkey in https://github.com/pimcore/pimcore/pull/19208
New Contributors
- @wwnorden made their first contribution in https://github.com/pimcore/pimcore/pull/19111
- @simonkey made their first contribution in https://github.com/pimcore/pimcore/pull/19208
Full Changelog: https://github.com/pimcore/pimcore/compare/v12.3.9...v12.3.10
Security Fixes
- Improve unserialize security in Hotspot Image
- Deserialization of Untrusted Data in pimcore/pimcore
- Harden field name validation
- Improve sql concatenation in Custom Reports
- Restrict allowed classes when unserializing the admin session token
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]