November 2024Deprecated support for IBM i v7r2 due to openssl 1.1.1 deprecation by IBM. All IBM i >= v7r3 must use at least OSS base 7.3 to be able to install/upgrade.FixedZend Server Z-Ray Database Queries failed to update placeholder value bindings in queries view when PDOStatement::bindValue() was called multiple times for the same placeholder.JQD excessive memory consumption when jobs failed in combination with redirectsJQD crashes when running HTTPS jobs when Zend Server was used in cluster mode with MySQL databasee-mail configuration testingFixed e-mail notifications for Zend Server JobQueue eventsMonitor rules import, e-mail address export/import in monitoring rulesAddedPHP directive max_multipart_body_parts in Zend Server GUI. Parameter has been added as PHP security fixChangedZend Server GUI, Plugins Gallery, change the plugin's package download url from static.zend.com to api-plugins.zend.comUpdatedPHP ExtensionsLinux memcached 3.2.0mongodb (php-specific) 1.19.1/1.16.2/1.11.1redis 6.0.2ssh2 1.4.1Windows imagick 3.7.0redis 6.0.2 (php >= 7.2) PHP and Zend Server dependency componentsLinux, IBM i (selected components only) lighttpd 1.4.76zlib 1.3.1libxml2 2.11.8libssh2 (where needed) 1.11.0openldap (selected distros only) 2.5.18freetype 2.13.2libimagic 6.9.13.11libsodium 1.0.20libzip 1.10.1xerces 3.2.5IBM i builds linked with OpenSSL 3.Windows httpd 2.4.62libzip 1.10.1curl 8.10.1imagemagick 7.1.0-18Backported PHP CVE fixesPHP 7.4.33.7 changesCGIFixed bug GHSA-p99j-rfp4-xqvq: Bypass of CVE-2024-4577, Parameter Injection Vulnerability. (CVE-2024-8926)Fixed bug GHSA-94p6-54jq-9mwp: cgi.force_redirect configuration is bypassable due to the environment variable collision. (CVE-2024-8927)FPMFixed bug GHSA-865w-9rf3-2wh5: Logs from childrens may be altered. (CVE-2024-9026)SAPIFixed bug GHSA-9pqp-7h25-4f32: Erroneous parsing of multipart form data. (CVE-2024-8925)PHP 7.3.33.12, 7.2.34.20, 7.1.33.24 changesCGIFixed bug GHSA-p99j-rfp4-xqvq: Bypass of CVE-2024-4577, Parameter Injection Vulnerability. (CVE-2024-8926)Fixed bug GHSA-94p6-54jq-9mwp: cgi.force_redirect configuration is bypassable due to the environment variable collision. (CVE-2024-8927)SAPIFixed bug GHSA-9pqp-7h25-4f32: Erroneous parsing of multipart form data. (CVE-2024-8925)