Sep
29
2026
XSS security problem in the Client UI
- If a partner AS2 id of an inbound partner contained HTML img tags the client UI tried to open this image in the transaction details
- Hardened the web interface against some possible XSS problems
- The statistic display has been reworked
- It is possible now to overwrite parts of the local security settings per partner and keep some settings from the default
- Dependencies: Updated BC to v1.86 (crypto API)
- Dependencies: Updated SLF4J to v2.0.20 (logging framework)
- Dependencies: Updated Caffeine to 3.3.0 (partner cache, serialization cache, preferences cache)
- Dependencies: Updated jfreechart to 1.5.6 (statistic display)