PowerFolder Server 16 SP7

  • Release Date: December 2021
  • Build Number: 16.7.100
  • Type: Service Pack Release


CVE-2021-44228

(lightbulb) PowerFolder is NOT affected by CVE-2021-44228.

In the software we do not use the affected library LOG4J, but instead use the Java system implemented logging mechanism.


Fixed Security Issue

(warning) This release contains major security fixes.


All production builds are starting from X.Y.100* and development builds (not for productive use) are starting from X.Y.1 - 99

* (Where X=Major software version and Y=Service pack number)

Upgrade Information

  • Please read this complete Release Notes and instructions before upgrading.
  • Please follow the regular upgrade documentation for Windows or Linux
  • Upgrading any previous version higher or equal to version 11.8
  • Cluster: Running different versions on the servers in the cluster is supported but limited to version >= 14.3.5

New Feature: Storage Migration during Uptime (BETA)

Automatic migration of data on backend storage
(warning)This function is currently marked as in beta state. Although heavy quality assurance was run on it, we still recommend to fully run this function in test systems only.

For more information, please visit our documentation.

Downgrade Information (optional)

  • In case a downgrade to a previous version is necessary:
    • For a downgrade you have to review our downgrade documentation.
    • Simply replace the PowerFolder-Server.jar file with that from the previous version you would like to run.
  • Log messages due to the higher schema version of database can be ignored:
    • [DatabaseMigrator]: Database layout version is newer than expected.

Changes

  • PFS-3887 - Fix display error due to folders with same names (own + shared) 
  • PFS-3912 - Fix file-links on files using "file_link.allow_uploads=false" 
  • PFS-3916 - Invite/Add account to group by email 
  • PFS-3906 - Accounts with read/write permission are able to restore files from recycle bin and version history 
  • PFS-3733 - Purge recycle bin should not be available to accounts without folder admin permission 
  • PFS-3919 - Change time of federation account merge timeframe to 20:00 to 7:00 or disable background run at all 
  • PFS-3913 - Fix expiry date in password protected file links 
  • PFS-3925 - Support BasicAuth in FileLink API 
  • PFS-3926 - Workaround for Zotero non-standard requests 
  • PFS-3928 - Account API: Include number of invitations 
  • PFS-3903 - Increase idle timeout in Jetty 
  • INT-593 - 5.6 Security fix in Upload form
  • INT-586 - 5.2 Security fix in Upload form
  • INT-585 - 5.5 Security fix in Upload form
  • INT-597 - 5.3 Security fix in Upload form
  • INT-595 - 5.7 Security fix in Terms of services
  • INT-594 - 5.6/5.8 Security fix in ONLYOFFICE connection
  • INT-589 - 4.8 Security fix in avatar logic