We are pleased to announce Kantega SSO Enterprise 5.5.

note

Read the upgrade notes for important information about the updating to version 5 (and you are upgrading from 4.x), and see the full changelog below.

Read the upgrade notes for important information about the updating to version 5 (and you are upgrading from 4.x), and see the full changelog below.

Compatible applications

Application

Compatible from version

Bamboo

7.0.1

Bitbucket

7.0.0

Confluence

7.4.0

Jira

8.8.0

Kantega SSO Enterprise for Bamboo Data Center March 2022

We are happy to announce that Kantega SSO Enterprise will be release for Bamboo Data Center this spring. The version is planned for release during March, when the Atlassian certification is completed. Data Center customers will be required to purchase a Data Center app license upon their next renewal.

Changelog

Security patches and bug fixes and GUI improvements.

Changes in 5.5.0

Improvements

Bug fixes

Changes in 5.5.2

Improvements

Bug fixes

Dependency updates

Dependency

Updated from version

Updated to version

Description

bouncycastle.bcprov

bouncycastle.bcprov-jdk15@140

org.bouncycastle.bcprov-jdk15to18@1.70

Dependency in Kerberos component of Kantega SSO Enterprise, org.simplericity.serberuhs. Our internal managed fork of serberuhs contains the new updates.

org.bouncycastle.bcpkix

bcpkix-jdk15on@1.59

org.bouncycastle.bcpkix-jdk15to18@1.70

Dependency in SAML component of Kantega SSO Enterprise

Security vulnerabilities patched

The dependency patching resolved the following vulnerabilities:

Vulnerabilities

Vulnerable dependency

Fix dependency

CVE-2013-1624

bouncycastle.bcprov-jdk15@140 in org.simplericity.serberuhs

org.bouncycastle.bcprov-jdk15to18@1.70

CVE-2020-26939,
CVE-2020-15522
CVE-2020-26939
CVE-2018-1000180,
CVE-2018-1000613

bcpkix-jdk15on@1.59

org.bouncycastle.bcpkix-jdk15to18@1.70

CWE-200

commons-codec:commons-codec@1.3 in org.simplericity:serberuhs

commons-codec:commons-codec@1.15

Changes in 5.5.3

Improvements

Bug fixes

Security vulnerabilities patched

Audit and update NPM packages and one maven dependency. The following vulnerabilities were patched:

Vulnerabilities

Dependency

Package

CVE-2021-3807

ansi-regex:4.1.0

pkg:npm/ansi-regex@4.1.0

CVE-2020-28469
CWE-400

glob-parent:3.1.0

pkg:npm/glob-parent@3.1.0

CVE-2020-15168
CVE-2022-0235

node-fetch:2.6.1

pkg:npm/node-fetch@2.6.1

CVE-2022-0122
NPM-1006852
NPM-1006854

node-forge:0.10.0

pkg:npm/node-forge@0.10.0

CVE-2021-23382

postcss:7.0.39

pkg:npm/postcss@7.0.39

CVE-2019-12400
CVE-2021-40690

org.apache.santuario:xmlsec:2.0.10)

pkg:maven/org.apache.santuario/xmlsec@2.0.10

Changes in 5.5.4

Bug fixes