Skip to content

Commit 77322dc

Browse files
committed
Update translations / version / copyright info and change log
1 parent c42459a commit 77322dc

File tree

15 files changed

+33
-14
lines changed

15 files changed

+33
-14
lines changed

CHANGELOG.md

Lines changed: 24 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,13 +7,22 @@ All notable changes to this project will be documented in this file.
77
### Notes
88

99
- To improve security we have deciced to allow users to rename the default admin user. And use a new user "hestia-web" to become the default user to run Hestia on.
10-
- Dropped support Debian 10 due to EOL
10+
-
11+
- In initial versions of HestiaCP we had Jailed SSH enabled via Jailkit. It had major disadvantages we have decided it to replace with Bubble Wrap. Users running Jailed SSH in the past are adviced to run the migration script! Found in /usr/local/hestia/upgrade/manual/migrate_jailkit_to_bubblewrap.sh. See #4698
12+
- We are aware that Cgroups are currently not working as it should be. It works fine if you login with SSH as the user how ever it doesn't work for PHP-FPM yet.
13+
- Dropped support Debian 10 due to EOL.
14+
15+
### Security
16+
17+
- Fix issue where CIRD was not propperly validated CVE-XXXX-XXX-XXX
18+
- Restrict PHP-FPM permissions to a new user to prevent permission escalation to admin users. CVE-XXXX-XXX-XXX
19+
- Solve security issues where restart flag did accecpt unvalidated values. CVE-XXXX-XXX-XXX
1120

1221
### Features
1322

1423
- Added support for PHP 8.4
1524
- Add support for Ubuntu 24.04 Noble release (#4411 #4451)
16-
- Add support for Jailed SSH (#4052 #4245) @rjd222
25+
- Add support for Jailed SSH (#4052 #4245, #4698 #4687)
1726
- Implement CLI for Quick Install Apps (#4443)
1827
- Add support for Directadmin / Cpanel imports ( #4177 #4415 #4426 #4252 #4241)
1928
- Add support for Increamental Backups via Restic
@@ -67,11 +76,21 @@ All notable changes to this project will be documented in this file.
6776
- Improve Owncloud templates (#4572)
6877
- Improve security Quick Install Apps (#457 #4569 #4568 #4567 #4566 #4565 #4564 #4563)
6978
- Add hestia-mail to hestia-users group and create hestia-users group on new install #4540 #4531
79+
- Fix translations MariaDB / PHPMyadmin (#4725)
80+
- Some left overs from the old admin user still remaind (#4721)
81+
- Disallow ` character in cronjobs to avoid errors in cron list #4708
82+
- Drop Maxmind high-risk-ip-sample-list (#4692)
83+
- Hardening of installer security and improving usability (#4690)
84+
- White label for file manager (#4681) @MaxiZamorano
85+
- Fixed with cronjob v-add-letsencrypt-domain created new cronjob onder "admin" user that didn't have sudo permisions
86+
- Customization of the file manager with interface improvements (#4678) @MaxiZamorano
87+
- Fix: Proftpd FTP Usage is showing incorrect information (#4672)
88+
- template for using webasyst with nginx+php-fpm (#4660)
7089

7190
### Depencies
7291

73-
- Update hestia-nginx to 1.27.0
74-
- Update hestia-php to 8.3.9
92+
- Update hestia-nginx to 1.27.3
93+
- Update hestia-php to 8.3.16
7594
- Update Roundcube, Filegator, Snappy mail to the latest version
7695
- Update Quick Installer apps to latest version (#4594)
7796

@@ -114,7 +133,7 @@ All notable changes to this project will be documented in this file.
114133

115134
### Security
116135

117-
- Restrict PHP-FPM permissions to a new user to prevent permission escalation to admin or other users [CVE-xxxx-xxxxx](https://huntr.com/bounties/21125f12-64a0-42a3-b218-26b9945a5bc0/)
136+
- Restrict PHP-FPM permissions to a new user to prevent permission escalation to admin or other users [CVE-2023-5839](https://huntr.com/bounties/21125f12-64a0-42a3-b218-26b9945a5bc0/)
118137
- Reduce Nginx keepalive_requests to 1000 ([Nginx default](https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/#http2_max_concurrent_streams)) to limit risks of [CVE-2023-44487](https://www.cve.org/CVERecord?id=CVE-2023-44487)
119138

120139
### Bug fixes

install/upgrade/upgrade.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ multiphp_v=("5.6" "7.0" "7.1" "7.2" "7.3" "7.4" "8.0" "8.1" "8.2" "8.3" "8.4")
4343

4444
# Check if update is required by matching versions if version != current version run update
4545
# Set version of phpMyAdmin to install during upgrade if not already installed
46-
pma_v='5.2.1'
46+
pma_v='5.2.2'
4747

4848
# Set version of phppgadmin to install during upgrade if not already installed
4949
pga_v='7.14.6'

src/deb/hestia/control

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
Source: hestia
22
Package: hestia
33
Priority: optional
4-
Version: 1.9.0~beta1
4+
Version: 1.9.0
55
Section: admin
66
Maintainer: HestiaCP <info@hestiacp.com>
77
Homepage: https://www.hestiacp.com

src/deb/hestia/copyright

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ Upstream-Name: hestia
33
Source: https://www.hestiacp.com
44

55
Files: *
6-
Copyright: 2018-2023, Hestia Control Panel <info@hestiacp.com>
6+
Copyright: 2018-2025, Hestia Control Panel <info@hestiacp.com>
77
License: GPL-3.0+
88
Remarks: Hestia Control Panel is a fork from VestaCP, special thanks to vestacp.com and Serghey Rodin
99

src/deb/nginx/control

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
Source: hestia-nginx
22
Package: hestia-nginx
33
Priority: optional
4-
Version: 1.27.2
4+
Version: 1.27.3
55
Section: admin
66
Maintainer: HestiaCP <info@hestiacp.com>
77
Homepage: https://www.hestiacp.com

src/deb/nginx/copyright

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ Upstream-Name: hestia
33
Source: https://www.hestiacp.com
44

55
Files: *
6-
Copyright: 2018-2023, Hestia Control Panel <info@hestiacp.com>
6+
Copyright: 2018-2025, Hestia Control Panel <info@hestiacp.com>
77
License: GPL-3.0+
88
Remarks: Hestia is a fork from VestaCP, special thanks to vestacp.com and Serghey Rodin
99

src/deb/php/control

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
Source: hestia-php
22
Package: hestia-php
33
Priority: optional
4-
Version: 8.3.13
4+
Version: 8.3.6
55
Section: admin
66
Maintainer: HestaCP <info@hestiacp.com>
77
Homepage: https://www.hestiacp.com

src/deb/php/copyright

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ Upstream-Name: hestia
33
Source: https://www.hestiacp.com
44

55
Files: *
6-
Copyright: 2018-2023, Hestia Control Panel <info@hestiacp.com>
6+
Copyright: 2018-2025, Hestia Control Panel <info@hestiacp.com>
77
License: GPL-3.0+
88
Remarks: Hestia is a fork from VestaCP, special thanks to vestacp.com and Serghey Rodin
99

src/deb/web-terminal/control

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
Source: hestia-web-terminal
22
Package: hestia-web-terminal
33
Priority: optional
4-
Version: 1.0.1
4+
Version: 1.0.2
55
Section: admin
66
Maintainer: HestiaCP <info@hestiacp.com>
77
Homepage: https://www.hestiacp.com

src/deb/web-terminal/copyright

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ Upstream-Name: hestia
33
Source: https://www.hestiacp.com
44

55
Files: *
6-
Copyright: 2018-2023, Hestia Control Panel <info@hestiacp.com>
6+
Copyright: 2018-2025, Hestia Control Panel <info@hestiacp.com>
77
License: GPL-3.0+
88
Remarks: Hestia is a fork from VestaCP, special thanks to vestacp.com and Serghey Rodin
99

0 commit comments

Comments
 (0)