Crowd 5.1 Upgrade Notes

Here are some important notes on upgrading to Crowd 5.1. To learn about new features, see the release notes.

 アップグレード ノート

次の重要な情報をご確認ください。

Crowd 5.1.0: Critical Security Misconfiguration Vulnerability - CVE-2022-43782

CVE-2022-43782 was addressed in Crowd 4.4.4. No additional actions are needed after the upgrade.

However, we recommend that you review Remote Addresses of the crowd application (Crowd console) and remove addresses that are no longer needed. 

Crowd 5.1.0: Removing algorithms used for password encryption and migrating to the default one

In Crowd 5.1.0, we’ve removed the following algorithms used for password encryption: 

  • DES/CBC/PKCS5Padding

  • DESede/CBC/PKCS5Padding

The following one is still supported:

  • AES/CBC/PKCS5Padding

The removed algorithms will also be automatically migrated to the supported one during upgrade.

If you don’t want to migrate and instead keep using the removed algorithms, start Crowd with the following flag:

-Dcrowd.encryption.upgrade.disabled=true

For more info on password encryption, see Password encryption.

 サポート対象プラットフォーム

We're deprecating the built-in HSQL 1.x database. In the next version of Crowd, we'll end support for it. The HSQL database will be upgraded to HSQL 2.7.x.

アプリ開発者向けの情報

There aren't any important changes for app developers in this release.

最終更新日 2023 年 8 月 3 日

この内容はお役に立ちましたか?

はい
いいえ
この記事についてのフィードバックを送信する
Powered by Confluence and Scroll Viewport.