New Appliance Release 15.1.0.1
Updates
A new SEPPmail Appliance release has been published. Please see the revision history and the extended release notes for further details.
A quick-fix release for 15.1.0 was necessary because of an error in the GINA domain settings page in the Admin GUI.
Hotfix release 15.1.0.1 (Released 2026-09-29)
Admin
- Fixed internal server error in edit GINA domain page.
Release 15.1.0 (Released 2026-09-28)
Admin
- Improved monitoring of LDAP database growth to help detect abnormal storage increases before available disk space becomes critical.
- Improved tenant-specific administration so delegated administrators can access only the accounts associated with their assigned tenant.
- Added a connection test for external keyserver settings to simplify configuration verification.
Background tasks
- Added improved administrator notification when an email backup cannot be completed.
- Added support for notifying communication partners about expiring certificates and facilitating certificate renewal.
- Extended disk-space monitoring to provide notifications when the LFM storage area approaches its configured capacity limit.
Database
- Adjusted LDAP synchronization settings to improve operation on medium and large installations.
Libraries
- Update OpenSSL to version 3.5.8
- Update OpenSSH sshd to version 10.4
RestAPI
- Added auditing capabilities for REST API requests to improve traceability of API activity.
- Corrected an incomplete API definition for cryptographic certificate information.
Rule engine
- Added message metadata that records actions performed during mail processing, allowing downstream applications to identify how a message was handled.
- Added PostgreSQL integration capabilities for Rule Engine custom commands, enabling controlled database lookups and updates for supported use cases.
Refactoring
- Modernized the internal implementation used for certificate revocation checks.
Security
-
Affected versions: ≤15.0.6.1 - CVE-ID: Pending - CVSS Score: 9.9
Description: Insufficient authorization controls in a cryptographic management API could allow an authenticated user with limited permissions to perform operations beyond their intended scope, potentially affecting system-wide trust configuration.
Fix Description: Restrict access to the REST endpoint/crypto/rootcato MSP tokens. -
Affected versions: ≤15.1.0 - CVE-ID: Pending - CVSS Score: 7.1
Description: Insufficient output sanitization in the log viewer could allow specially crafted message data to execute unintended browser-side content when viewed by an administrator.
Fix Description: Escape all external data to prevent content execution. -
Updated internal command execution to use safer command-handling mechanisms.
Webmail
- Corrected the styling of generated email notifications to ensure a consistent appearance.
- Added support for restricting file types that external communication partners can upload through GINA.
← Back