The 5.7 branch of Magnolia reached End-of-Life on December 31, 2023, as specified in our End-of-life policy. This means the 5.7 branch is no longer maintained or supported. Please upgrade to the latest Magnolia release. By upgrading, you will get the latest release of Magnolia featuring significant improvements to the author and developer experience. For a successful upgrade, please consult our Magnolia 6.2 documentation. If you need help, please contact info@magnolia-cms.com.

Magnolia CMS 5.7.22 is the third Extended end-of-life (EEoL) maintenance release, which brings security updates.

We keep the details of security fixes private in line with our security policyContact our Support team if you need more information.

Should you require access to the updates of 5.7 under the EEoL conditions, please contact your sales representative.

CSRF security improved

Since this release, you can configure the httpOnly and secure attributes on the CSRF cookie. Furthermore, the implementation has been hardened to mitigate session fixation attacks.

For more details, see Filters: CSRF token security.

MAGNOLIA-8511, MAGNOLIA-8512

Others

If you are upgrading from an earlier version, read Upgrading to Magnolia 5.7.x first and check the Known issues section on the page.

Changelog

See the 5.7.22 changelog for all the changes.

Updated modules

  • Community Edition 5.7.22
  • Enterprise Edition 5.7.22
  • Magnolia 5.7.22
  • UI 5.7.22

Acknowledgements

The Magnolia team would also like to thank everyone who reported issues, contributed patches or simply commented on issues for this release.

  • No labels