Release Notes 18.12.18

Apache OFBiz® 18.12.18, released in March 2025, is the 18th release of the 18.12 series, which has been feature-frozen since December 2018, receiving only bug fixes.

Release Notes - OFBiz - Version 18.12.18

Sub-task

  • [OFBIZ-9089] - Unit test case for service - createProductFeatureType
  • [OFBIZ-12080] - Secure the uploads
  • [OFBIZ-13092] - [SECURITY] (CVE-2024-36104) Path traversal leading to RCE
  • [OFBIZ-13147] - Prevent URL parameters manipulation
  • [OFBIZ-13180] - [SECURITY] Several CVEs in Apache Tomcat
  • [OFBIZ-13192] - Issues when uploading SVG files

Bug

  • [OFBIZ-13168] - String to numeric conversion does not support non-breaking spaces

New Feature

Improvement

  • [OFBIZ-13213] - Refactor ControlFilter class without functional changes