HestiaCP 1.10.2 Released: Security Patches and DNS Fixes

Published by

HestiaCP has released version 1.10.2, a service update addressing security vulnerabilities and DNS issues shortly after the major 1.10.0 update. This release specifically fixes two session-isolation vulnerabilities in the file manager, preventing unauthorized access between users during batch downloads and chunked uploads. Additionally, the SOA EXPIRE value in the Bind DNS configuration has been corrected for better compliance, and a bug in the upgrade script that caused internal version conflicts has been resolved. Users on the 1.10.x branch can apply these updates through the standard upgrade process



HestiaCP 1.10.2 Released: Security Patches and DNS Fixes

HestiaCP 1.10.2 has arrived as a service release, dropping just 17 hours after the massive 1.10.0 major update to address three immediate regressions. The hotfix patches two session-isolation vulnerabilities in the bundled file manager that could allow cross-user access to batch downloads and chunked uploads. It also corrects the Bind DNS SOA EXPIRE value to 1,209,600 seconds for better compliance and fixes a regression where sourcing /etc/os-release could overwrite the internal version variable during upgrades. Users on the 1.10.x branch can apply the changes now via the standard upgrade path.

HestiaCP 1.10.2 Released: Security Patches and DNS Fixes @ Linux Compatible