Release Notes 24.09.01

Apache OFBiz® 24.09.01, released in April 2025, is the first release of the 24.09 series, which has been feature-frozen since September 2024, receiving only bug fixes.

Sub-task

  • [OFBIZ-12080] - Secure the uploads
  • [OFBIZ-12127] - Refactor MacroFormRenderer to use RenderableFtlElements for drop down fields
  • [OFBIZ-13092] - [SECURITY] (CVE-2024-36104) Path traversal leading to RCE
  • [OFBIZ-13131] - Test 2.3.34 FreeMarker release
  • [OFBIZ-13174] - Helveticus: jsTree visual glitch on hover
  • [OFBIZ-13192] - Issues when uploading SVG files

Bug

  • [OFBIZ-12296] - rest/control/main generates a 404
  • [OFBIZ-13143] - Webtools FindGeneric, sort field is break on list
  • [OFBIZ-13149] - Example charts don't work
  • [OFBIZ-13150] - example/control/ManagePortalPages?parentPortalPageId=EXAMPLE works but reports an error
  • [OFBIZ-13169] - Rainbowstone/Helveticus: advanced search cannot be open in modals
  • [OFBIZ-13191] - Bug persisting uploaded files with service attachUploadToDataResource
  • [OFBIZ-13210] - Registration of an user in ecommerce throws an error
  • [OFBIZ-13211] - OFBiz Setup failing to setup the product store
  • [OFBIZ-13218] - Correct the typo of entity name in cancelReplacementOrderItems method

New Feature

Improvement

  • [OFBIZ-12821] - Improvement of the Check xml tag
  • [OFBIZ-13133] - Allow to use GroovyDsl in FlexibleStringExpander
  • [OFBIZ-13146] - Slimdown use of ${groovy: }
  • [OFBIZ-13173] - Add display result format for auto-completion on lookup
  • [OFBIZ-13178] - Update end bracket detection en groovy scriplet
  • [OFBIZ-13179] - Improve ViewHandler interface
  • [OFBIZ-13182] - Optimization on removeJob service
  • [OFBIZ-13185] - Bug in Log4j
  • [OFBIZ-13196] - Upgrade to 2.3.34 FreeMarker release
  • [OFBIZ-13205] - ProjectServices: Project creation with template id should call "createProject" instead of "createProjet"
  • [OFBIZ-13201] - Migrate Build Scan publication to develocity.apache.org