Dear all,
DHIS2 version 42.5.1 is out as a HOTFIX to address the following security advisories:
-
GHSA-pwmg-mvjw-4m23: SQL injection vulnerability
-
GHSA-6785-hj47-c27h: Reflected cross-site scripting (XSS) vulnerability
-
GHSA-3fr2-wvqx-cmr5: Unsafe Java deserialization vulnerability
→ please note that the above links will not work until the advisories have been made publicly available
It also bundles the following stability fix:
- DHIS2-21604: Generating a Personal Access Token causes DHIS2 42.5 service corruption
This is the latest stable release for version 42, and supersedes releases 42.0 to 42.5.
These hotfixes are provided to make it easy for you to keep your system secure; provided you keep up to date with the latest patch versions.
Thanks!
DHIS2 Release Team
| Release Information | Links |
|---|---|
| Release Note | Patch 42.5.1 Release Note |
| Upgrade notes | 42 Upgrade notes |
| Download release and sample database | Downloads - DHIS2 |
| Documentation | Home - DHIS2 Documentation |
| Source code on Github | Release 2.42.5.1 · dhis2/dhis2-core · GitHub |
| Demo instance | Login app | DHIS2 |
| Docker | docker pull dhis2/core:42.5.1for more docker image variants see dockerhub |