- 26 Nov 2024
- 1 Minute to read
- DarkLight
- PDF
November Release 24.R2
- Updated on 26 Nov 2024
- 1 Minute to read
- DarkLight
- PDF
Fixes and other updates
Issue OSRAC-6643: Authorization cookie size in Presentation Service exceeded
In Risk Analytics Presentation Service, if the environment contained more than 26 roles and the size of the authorization cookie exceeded the maximum default size, the web browser rejected the authorization cookie. Consequently, the user was unable to log in.
This issue has been fixed.
Issue OSRAC-6665: Fixed vulnerability in signature
A digital signature using an HMAC-SHA256 algorithm has been added to the XML export/import files to prevent importing malicious data when XML files are modified. Validation has been improved to avoid displaying exception information when the signature is verified.
Issue OSRAC-6692: Email messages rejected because not verified
When using email alert notifications configured through the Risk Analytics user interface, the email alerts were not processed. This was caused by a discrepancy between the configured sender email address and the one authorized by the SMTP server
This issue has been fixed. The SMTP configuration in Risk Analytics deployment scripts has been adapted.