Hotfixes filtered by
Nuxeo Platform LTS 2023
Nuxeo Platform LTS 2021
Nuxeo Platform 11.x
Nuxeo Platform LTS 2019
Nuxeo Platform LTS 2017
Nuxeo Platform LTS 2016
Nuxeo Platform LTS 2015
Nuxeo Platform 6.0
Nuxeo Platform 5.8
Nuxeo Platform 5.6
All HotFixes
Nuxeo 5.8.0-HF27
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Fix totalSize for Elasticsearch query with limit 0
* More robustness when trying to adapt a Picture document with no blob
* Use System property to initialize logs folder, if defined
* Fix document update with a DnD of the same file
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16761
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 2:19:05 PM
Nuxeo 5.8.0-HF32
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statement is included in this hotfix.
Main corrections provided:
* Fix XSS issues
* Fix NPE in Elasticsearch indexing worker
* Normalize document name when looking for child
* Fix Routing POJOs Serialization for Redis writing
* Fix UnifiedCachingMapper to take cluster invalidations in account
* Fix page size selector values displayed on content views
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16815
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 2:17:14 PM
Nuxeo 5.8.0-HF41
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix XSS issues
* Fix potential NPE in nuxeo-select2.js
* Fix NPE in TemplateInitListener when no blob is attached to template document
* Fix version comparison in ConfigurationGenerator.checkJavaVersion
* Make sure sensitive directories are readable only by admin
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=17863
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 2:14:13 PM
Nuxeo 5.8.0-HF19
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Fix startup when setting nuxeo.force.generation to once
* Make FulltextUpdaterWork.IndexAndText class Serializable
* Fix AbstractWork logging under Redis
* Fix WorkManager + Redis startup
* Fix fetching of nodes marked absent in persistence context
* Cache result count from the History content view
* Fix dueDate display to use the timezone in open tasks layout
* Add a way to log slow NXQL queries
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16410
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 10:05:15 AM
Nuxeo 5.8.0-HF02
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix versioning failure if no versioning options are specified
* Fix files drag'n drop if local configuration is activated
* Fix error when uploading file with empty mimetype by drag'n drop
* Fix tab cache reset when finished task
* Fix preview JS error
* Non-SNAPSHOT Marketplace package install should not force other packages upgrade to SNAPSHOT version
* Multiple fixes in Nuxeo Drive client and server
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=15218
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 10:02:56 AM
Nuxeo 5.8.0-HF40
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix access to the Update Center
* Fix Publish tab when a domain does not hold a SectionRoot child
* Fix date formatting
* Fix authorization of automation operation 'Traces.Get'
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=17691
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:58:10 AM
Nuxeo 5.8.0-HF28
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Fix Rebuild index for the whole repository
* Fix Tag Search
* Fix position of copied doc in ordered folder
* Use the same entry name encoding for all zip exports
* Fix Web template parameters save
* Fix Content-Disposition encoding on IE >= 10
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16768
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:56:36 AM
Nuxeo 5.8.0-HF34
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
A DDL statement for PostgreSQL is included in this hotfix.
Main corrections provided:
* Support Oracle 12 in Nuxeo persistence
* Fix Redis unlocking
* Fix PDF rendition republishing
* Fix list widget validation logics
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=17162
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:55:59 AM
Nuxeo Security HotFix 1
This package fixes the RichFaces CVE-2013-2165 flaw.
JBoss RichFaces has a known flaw related to deserialization:
* https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2165
Details of the patch are here:
* http://www.bleathem.ca/blog/2013/07/richfaces-CVE-2013-2165.html
Note that Nuxeo 5.6.0-HF27 and 5.8.0-HF-01 automatically include this security fix.
It is strongly recommended to install this package.
Alternatively, you can manually update Nuxeo's RichFaces jars.
Please refer to the following documentation to do so:
* http://doc.nuxeo.com/x/bIAPAQ
Credit to Arun Neelicattu and David Jorm of Red Hat for reporting this issue.
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:54:45 AM
Nuxeo 5.8.0-HF26
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Fix Elasticsearch ILIKE
* Fix LIKE operator in Elasticsearch with special characters
* Fix monitoring of repository events
* Improve performance of document adapter lookup
* Fix problem where Administrator is able to delete a version with proxies
* Upgrade antisamy to handle HTML5 tags
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16752
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:53:11 AM
Nuxeo 5.8.0-HF39
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Drive: sync roots computation fail if user looses access on one of them during computation
* Drive: add lock info in FileSystemItem
* Lock / unlock events are not detected by GetChangeSummary
* Fix persistent XSS in relation target URL
* Remove HTML in "Text Editor" OpenSocial Gadget
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=17661
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:52:16 AM
Nuxeo 5.8.0-HF37
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix navigation between DM and DAM
* Fix clearTask method when task does not exist anymore
* Fix Drive sync roots computation failure if user looses access on one of them during computation
* Optimize LDAP requests not to fetch all attributes
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=17529
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:50:43 AM
Nuxeo 5.8.0-HF29
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* SQL directories now set autocommit mode
* Make DefaultPermissionProvider thread-safe
* Prevent race condition on cluster quartz initialization
* Fix rendering of user suggestion widget inside lists in view mode
* Fix WebDAV creation for folders with semicolon
* Prevent token authentication for anonymous user
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16778
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:50:35 AM
Nuxeo 5.8.0-HF38
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix infinite loop in MySQL NX_ACCESS_ALLOWED
* Make BasicAuthenticator send a dedicated HTTP status code in case of LDAP Connection reset
* Make use of java.io.tmpdir
* Fix attributes fetching for LDAP references
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=17639
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:49:05 AM
Nuxeo 5.8.0-HF05
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix error "already checked-in" when publishing rendition
* Fix action widgets configuration
* Fix textarea widget configuration for the "escape" property
* Fix empty directory entry label exception
* Fix redirection to logout when Nuxeo URL uses HTTPS
* Fix user declation as a tenant administrator
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=15515
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:45:16 AM
Nuxeo 5.8.0-HF30
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Better handling of socket exceptions
* Fix quota initial statistics computation of document count
* Fix quota computation when restoring a version
* Fix setting of max quota size
* Improvements in Elasticsearch indexing
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16794
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:40:04 AM
Nuxeo 5.8.0-HF15
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statement is included in this hotfix.
Main corrections provided:
* Allow to disable referrals resolution in LDAP Directory
* Fix Nuxeo startup which takes too long when template rendering addon is installed
* Fix silent exception when adding a user in multi-tenant mode
* Remove synchronization on Nuxeo class loader
* Avoid contention on getComponentProvidingService
* Fix favicon display in IE11
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16220
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:38:29 AM
Nuxeo 5.8.0-HF13
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix setting ACP on versions
* Make BinaryScrambler implementations must be Serializable
* Fix escape handler in Automation Properties loader
* Fix exception when searching a date like number in the suggest box
* Fix cache invalidation after document lock/unlock
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16116
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:36:08 AM
Nuxeo 5.8.0-HF33
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statement is included in this hotfix.
Main corrections provided:
* Fix NPE in BaseIndexingWorker during Elasticsearch inititialization
* Fix Elasticsearch failure to index document with token field bigger than 32k
* Fix Elasticsearch async indexing job failure when using Redis
* Fix Error while downloading a Note which title contains slash '/'
* Fix Incorrect encoding of BIRT editParams page
* Fix the display of group members in edit mode
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16922
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:34:00 AM
Nuxeo 5.8.0-HF23
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Delete temporary files when leaving a thread
* Fix wrong view property for user_group_prefixed_suggestion layouts
* Fix NPE in ClipboardActionsBean.getCanPaste method
* Fix XSS issue on document library gadget
* Reset the document icon when the main attached file is removed
* Fix permission error when restoring a document
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16716
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:30:12 AM
Nuxeo 5.8.0-HF22
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Fix ClientException when serializing to json a DocumentModel having a null reference
* Fix pathOptimizationsVersion attribute merge
* Isolate spi and impl package in OSGi for Automation Client
* Fix crash when too many content changes are requested.
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16519
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:26:22 AM
Nuxeo 5.8.0-HF21
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Fix use of native PostgreSQL uuids for document ids
* Fix Studio validation on snapshot hotfix distribution
* Fix NPE when setting quota
* Fix hardcoded usage of Workspace type to compute available templates
* Fix em tag display in Notes
* MySQL 5.6 requires columns shorter than 255 when they are indexed
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16511
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:23:17 AM
Nuxeo 5.8.0-HF36
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix XSS due to injected language URL parameter
* Fix XSS in workflow result displaying user name
* Fix XSS in select2 autocompletion
* Rollback transaction on WebEngine/JAX-RS error
* Fix list widget with tiny mce editor in toggleable form
* Do not hide empty content view when there are filtering criteria
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=17428
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:22:05 AM
Nuxeo 5.8.0-HF01
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix ACLR cache corruption on SQLServer
* Fix complex property access after schema update
* Fix Oracle node identity detection
* Fix event listener priority override
* Fix missing filename when uploading Blob via Automation.
* Multiple fixes in Nuxeo Drive client and server
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=15111
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:20:47 AM
Nuxeo 5.8.0-HF35
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
Main corrections provided:
* Fix Redis cache invalidateAll failure with jedis exception
* Fix Redis unlocking
* Fix NPE in UserManagementActions
* Fix drive root unsync when synchronizing parent root
* Fixes for Quota addons
* Return directory references with deterministic order
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=17212
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:19:00 AM
Nuxeo 5.8 Security Update 2015-02-27
Critical security issues fixed:
* Fix security issue on "scripts" servlet
* Fix XXE in Nuxeo
* Fix XXE in Seam
* Fix remote code execution issue
Other fixes included in this hotfix:
* Add alert in suggestion widget when an error occurs
* Fix total documents in Elasticsearch / Admin Center
* Fix deletion of first item in the list widget
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16798
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:19:00 AM
Nuxeo 5.8.0-HF18
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
DDL statements for PostgreSQL and SQL Server are included in this hotfix.
Main corrections provided:
* Make NX_IN_TREE stored procedure scale on PostgreSQL and SQL Server
* Fix NPE retrieving currentDocumentVersionInfo when current document is not set
* Fix missing new document after drag'n drop
* Upgrade Jedis library
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16310
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:17:09 AM
Nuxeo 5.8.0-HF24
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Expose position of document in OrderedFolder
* Fix AddPermission operation when inheritance is blocked
* Fix ElasticSearch indexing scalabity issue on Folderish document with loads of child documents
* Fix ElasticSearch parse failure on ecm:pos in OrderedFolder
* Disable agressive temporary files cleanup
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16728
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:15:18 AM
Nuxeo 5.8.0-HF25
Download and install the latest hotfix to keep your Nuxeo up-to-date
Changes will take effects after restart.
No DDL statements is included in this hotfix.
Main corrections provided:
* Fix comments indexing when using Elasticsearch
* Fix possible NPE on Elasticsearch indexing
* Fix multiline property reading
* Fix User/Group suggestion widget in a List widget
* Fix TinyMCE with Internet Explorer 11
* Fix available faceted searches computation when the default faceted search is identical
Complete release note is available at:
https://jira.nuxeo.com/secure/ReleaseNote.jspa?projectId=10011&version=16734
For Nuxeo Platform 5.6, Nuxeo Platform 5.8
Updated on Jan 13, 2020, 9:13:45 AM