[Oskari-user] Oskari-server 2.5.3 released!

Mäkinen Sami (MML) sami.makinen at maanmittauslaitos.fi
Thu Dec 16 07:21:04 PST 2021


Hi everyone,

Earlier this week we released version 2.5.2 for the server regarding the Log4J vulnerability. The logging library has since released another version that fixes another vulnerability. While it's not as nefarious as the first one we decided to release a patch for Oskari as well. The vulnerability requires a setup that isn't used in the Oskari codebase directly but for peace of mind and to prevent possible application specific usage it's a recommended update nonetheless.

We also included a fix for a rare issue where layer removal for admins was broken on the system after configuring timeseries layer settings (specifically when configuring the range-UI and NOT configuring a vector source for metadata) for a WMS-layer.

Again updating just the server is enough to get the fixes included in 2.5.3 (https://oskari.org/documentation/updating).

Cheers,
    Sami
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.osgeo.org/pipermail/oskari-user/attachments/20211216/c8bc2736/attachment.html>


More information about the Oskari-user mailing list