HestiaCP 1.10.4 Fixes SFTP Rotation Bug and Security Leaks
HestiaCP 1.10.4 arrives as the fifth update in three weeks, delivering security hardening and critical bug fixes following the major 1.10.0 feature release. The version includes a vital patch for SFTP backup rotation where carriage return characters were breaking the file count, causing unbounded storage growth on remote backups. Security improvements prevent passwords from leaking into auth.log and journalctl by passing credentials through temporary files instead of command-line arguments, with reviewer extensions covering SMTP relay scripts. Additional changes disable Roundcube IMAP debug logging by default to save disk space, fix mail filter breaks caused by a missing imap_sieve plugin, and correct UI navigation errors in the admin panel.
HestiaCP 1.10.4 Fixes SFTP Rotation Bug and Security Leaks @ Linux Compatible
HestiaCP 1.10.4 Fixes SFTP Rotation Bug and Security Leaks
HestiaCP 1.10.4 has been released, addressing critical security issues and fixing a significant SFTP backup rotation bug that could lead to uncontrolled storage growth due to carriage return characters disrupting file counting. This update includes security enhancements to prevent password leaks by changing how credentials are handled, as well as disabling Roundcube's IMAP debug logging by default to conserve disk space. Additional fixes were made to mail filter functionality and UI navigation errors in the admin panel. Users are encouraged to upgrade promptly, especially those utilizing remote SFTP backups, as the update is crucial for maintaining system integrity and performance
