Add new attachment

Only authorized users are allowed to upload new attachments.

List of attachments

Kind Attachment Name Size Version Date Modified Author Change note
jpg
minor_update.jpg 356.6 kB 1 05-Dec-2023 05:32 Ada Csaba

This page (revision-45) was last changed on 15-Nov-2024 05:18 by Ben Spink

This page was created on 05-Dec-2023 05:32 by Ben Spink

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Difference between version and

At line 1 changed one line
!!REGARDING THE RECENT VULNERABILITY ANNOUNCEMENT AUGUST 10, 2023!
!!!__Update Bug on Windows__
Some versions of CrushFTP had a problem applying an update automatically. They would fail to rename ".jar" files on Windows operating systems. They would instead leave behind ".jar_tmp" files needing the "_tmp" manually removed from them. This has been fixed for a while, but if you are still on one of these older builds, you will be affected the next time you attempt the update. So you need to fix the jar filenames one time manually. Example: CrushFTP.jar_tmp -> CrushFTP.jar. Same for all other jars in plugins, plugins/lib folder, and the WebInterface folder has CrushTunnel.jar. Do all 3 locations entirely.
At line 3 removed 2 lines
If your CrushFTP version is less then 10.5.1, you are vulnerable. No exception. Look at your version number on the dashboard, and it must be 10.5.1 or higher to be safe. For reference, v6, v7, v8,v9...those numbers are less than v10.5.1. Yes, they are vulnerable! Anything below 10.5.1 is vulnerable.\\
The vulnerability CVE will be released soon. This vulnerability is critical because it does NOT require any authentication. It can be done anonymously and steal the session of other users and escalate to an administrator user. Its critical everyone updates ASAP! Other defaults related to loading DB drivers thata re not in your classpath has also changed. This means if your DB drivers are not part of your plugins/lib folder, they will not be loaded by CrushFTP. (Statistics DB if you changed it, SQL Users if you are using that, etc.)\\
At line 6 changed one line
!!Updating CrushFTP v10
!!Vulnerability Info
__November 11th, 2024 - (CVE - coming soon...pending)\\
V10 versions below 10.8.3 and V11 versions below 11.2.3 are vulnerable to a password reset email exploit. If an end user clicks the link, their account is compromised.
(CREDIT: Stratascale Cyber Research Unit)__\\
Once you update you must configure your allowed email reset URL domains.\\
v10:Preferences, WebInterface, MiniURL: Set an allowed list of domains, comma separated.\\
v11:Preferneces, WebInterface, Login Page: Set a domain pattern that is not just '*' as a '*' is no longer allowed.\\
----
April 19th, 2024 - CVE-2024-4040\\
CrushFTP v11 versions below 11.1 have a vulnerability where users can escape their VFS and download system files. This has been patched in v11.1.0. Customers using a [DMZ] in front of their main CrushFTP instance are partially protected with its protocol translation system it utilizes. A DMZ however does not fully protect you and you must update immediately. (CREDIT:Simon Garrelou, of Airbus CERT)\\
----
\\
!!FAQ:
•If I'm on v10.8.3+...do I need to upgrade to v11? No, 10.8.3+ are safe.\\
•If I'm on v10.6.1, or v10.3, or v10.5.5, am I vulnerable? Yes! Update immediately to 10.8.3+ or v11.2.3+.\\
\\
\\
!!Updating CrushFTP v11
At line 18 changed 2 lines
1.) Download CrushFTP10.zip from our download page. ([https://www.crushftp.com/early10/CrushFTP10.zip|https://www.crushftp.com/early10/CrushFTP10.zip])\\
2.) Give it the specific name `CrushFTP10_new.zip` and place this in the CrushFTP main folder. (Same location where you have your prefs.XML file)\\
1.) Download CrushFTP11.zip from our download page. ([https://www.crushftp.com/early11/CrushFTP11.zip|https://www.crushftp.com/early11/CrushFTP11.zip])\\
2.) Give it the specific name `CrushFTP11_new.zip` and place this in the CrushFTP main folder. (Same location where you have your CrushFTP.jar file)\\
At line 29 changed one line
!Changelog: [https://www.crushftp.com/version10_build.html]\\
!Changelog: [https://www.crushftp.com/version11_build.html]\\
At line 31 changed one line
!!Updating an old CrushFTP v9
!!Updating an old CrushFTP v10,v9 and prior
At line 33 changed one line
You need a v10+ license code first! If you are an enterprise customer, contact us for your code. Its free if your maintenance is current.
You need a v11 license code first! If you are an enterprise customer, contact us for your code. Its free if your maintenance is current.
\\
All prior versions of CrushFTP were also affected by this most recent vulnerability.\\
CrushFTP v10 info: [https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update]\\
Version Date Modified Size Author Changes ... Change note
45 15-Nov-2024 05:18 3.719 kB Ben Spink to previous
44 14-Nov-2024 10:56 3.693 kB Ben Spink to previous | to last
43 11-Nov-2024 10:22 3.679 kB Ben Spink to previous | to last
42 11-Nov-2024 06:03 3.649 kB Ben Spink to previous | to last
41 11-Nov-2024 06:02 3.643 kB Ben Spink to previous | to last
« This page (revision-45) was last changed on 15-Nov-2024 05:18 by Ben Spink
G’day (anonymous guest)
CrushFTP11 | What's New

Referenced by
LeftMenu

JSPWiki