2021.12.16 Release Notes
Product Features and Enhancements
| Reference Number(s) | Summary | Components |
|---|
| RIC-772 | Web Security | Web Security |
| | RIC-648 | OSS Security Vulnerabilities | Security Vulnerability |
| | | RIC-647 | CVE-2017-5662 XML External Entity (XXE) Injection | Security Vulnerability |
| | | RIC-646 | CVE-2021-28170 Improper Input Validation | Security Vulnerability |
| | | RIC-645 | CVE-2021-41079 Denial of Service (DoS) | Security Vulnerability |
| | | RIC-644 | CVE-2020-28491 Denial of Service (DoS) | Security Vulnerability |
| | | RIC-643 | CVE-2020-13954 Cross-site Scripting (XSS) | Security Vulnerability |
| | | RIC-642 | CVE-2020-25638 SQL Injection | Security Vulnerability |
| | | RIC-641 | [CVE-2016-1000031] Arbitrary Code Execution | Security Vulnerability |
| RIC-773 | SSO Portal | SSO Portal |
| | RIC-599 | SSO Portal Enhancements | SSO Portal |
| | | RIC-701 | Add Application Search to SSO Portal Home Page [BE] | SSO Portal |
| | | RIC-607 | Drag and drop applications in Persona Configuration | SSO Portal |
| | | RIC-606 | Launch applications from App Directory via single-click | SSO Portal |
| | | RIC-604 | Add sort to application list in persona config | SSO Portal |
| | | RIC-602 | Add Application Search to SSO Portal Home Page | SSO Portal |
| RIC-838 | Studio Jobs | Studio |
| | RIC-412 | Higher-level Studio Job Orchestration | Studio |
| | | RIC-428 | Decrease Job Runtime and Other Job Speed Improvements | Studio |
| RIC-491 | Studio Improvements | Studio |
| | RIC-409 | Update Studio Application Look and feel | Studio |
| | | RIC-675 | Grey out Access Group list and add access group button when unrestricted access is enabled | Studio |
| | | RIC-670 | Remove title from pages | Studio |
| | | RIC-669 | Use Chips for Linked SSO Apps | Studio |
| | | RIC-664 | Change Font from 'Roboto' to 'Inter' | Studio |
Feature Improvements
| Reference Number(s) | Summary | Components |
|---|
| RIC-632 | InCommon: Add timestamp to the date provided by Metadata Refresh | InCommon |
| RIC-659 | UI: Handle locale sorting | RIC |
| RIC-733 | BE: Improve GAL item validation | GAL |
Resolved Issues
| Reference Number(s) | Summary | Components |
|---|
| RIC-772 | Web Security | Web Security |
| | RIC-648 | OSS Security Vulnerabilities | Security Vulnerability |
| | | RIC-759 | CVE-2019-17195: nimbus-jose-jwt information disclosure | Security Vulnerability |
| | | RIC-745 | CVE-2013-5960: OWASP ESAPI MAC Validation Bypass | Security Vulnerability |
| | | RIC-744 | CVE-2019-17195: nimbus-jose-jwt improper check for unusual conditions | Security Vulnerability |
| | | RIC-742 | CVE-2020-13956: Apache HTTP Components Improper Input Validation | Security Vulnerability |
| | | RIC-741 | CVE-2020-28052: Bouncy Castle Comparison Using Wrong Factors | Security Vulnerability |
| | | RIC-740 | CVE-2021-22118: Spring Framework Privilege Escalation | Security Vulnerability |
| | | RIC-739 | CWE-20: Logback insufficient hostname verification | Security Vulnerability |
| | | RIC-738 | CVE-2020-8908: Guava information disclosure | Security Vulnerability |
| | | RIC-737 | CVE-2021-29425: Commons-IO directory traversal | Security Vulnerability |
| RIC-627 | Handle sorting on BE application-wide | Sorting |
| RIC-629 | Can't Clear out 'DATE' attribute from delegation profiles | People |
| RIC-631 | Update Profile Date attribute to not have a value | Delegations |
| RIC-658 | httpDELETE action should accept a request body | Connect |
| RIC-660 | History diff does not show new input parameter configuration | Connect |
| RIC-661 | On openLDAP servers, the Advanced Search Tool dropdown doesn't display all searchable options. | Search |
| RIC-662 | People: Change Password confirmation has unneeded "Save" button | People |
| RIC-691 | Permission errors in new architecture do not prevent loading | Portal |
| RIC-727 | IDP Challenge Question Setup: Weird "X" image being used, different than before. | IDP |
| RIC-729 | People: Sponsored accounts failing to load | People |
| RIC-732 | UI: Correctly handle type params for GAL items | GAL |
| RIC-754 | UI: need to URL encode path and query params for Connect file actions | Connect, Files |
| RIC-763 | Studio Double sidebar when leaving an application via breadcrumb with unsaved changes. | Studio |
| RIC-765 | Studio: Credential type dropdown not updating title to chosen type - only in Firefox. | Studio |
| RIC-784 | Cleanup locale sorting | Connect |
| RIC-806 | SMS incorrectly prepends dial prefix to numbers that already have a + code | Authentication |
| RIC-809 | IDaaS: SMS Configuration | Configuration, SMS |
| RIC-810 | Tenant Admin cannot update dialPrefix | Configuration, SMS |
Updated on Thu Jan 27 2022 08:02:13 GMT-0500 (Eastern Standard Time)