HestiaCP 1.9.8 Released: Security Hardening Follows Rapid 1.9.7 Patch Haul

Published by

HestiaCP has released version 1.9.8, following a previous update that addressed nine critical security vulnerabilities in version 1.9.7. The latest update includes security enhancements to access controls for the ROOT_USER account, cross-site scripting (XSS) fixes in notifications, and patches for command injection risks in the backup queue. Additionally, several functional bugs have been fixed, including issues with the SFTP jail feature, FTP certificate reloading, and JSON parsing errors. The release indicates an active development cycle, with users encouraged to apply the updates promptly for improved security and functionality



HestiaCP 1.9.8 Released: Security Hardening Follows Rapid 1.9.7 Patch Haul

HestiaCP released version 1.9.8, just two weeks after addressing nine critical CVEs in 1.9.7. The new update hardens access controls around the ROOT_USER account to prevent privilege escalation and patches cross-site scripting in notifications alongside command injection risks in the backup queue. Functional fixes address a regression in the SFTP jail feature that broke connectivity for jailed users, as well as broken FTP certificate reloading and corrupted JSON output from SSL queries.

HestiaCP 1.9.8 Released: Security Hardening Follows Rapid 1.9.7 Patch Haul @ Linux Compatible