Security Improvements

This section lists changes made to improve Sinch Contact Pro security.

Java-based open source libraries have been updated:

  • bcpkix-jdk15on 1.70 → 1.80
  • commons-codec 1.15 → 1.16.0
  • commons-compress 1.23.0 → 1.24.0
  • commons-lang3 3.12.0 → 3.13.0
  • httpclient 4.5.13 → 4.5.14
  • jackson-core 2.14.2 → 2.15.2
  • jaxws-rt 2.3.5 → 2.3.6
  • jersey-container-servlet 2.39 → 2.40
  • jmh-core 1.35 → 1.37
  • jna 5.12.1 → 5.13.0
  • json 20230227 → 20231013
  • log4j-api 2.19.0 → 2.20.0
  • mockrunner-jdbc 2.0.6 → 2.0.7
  • mssql-jdbc 9.2.1.jre8 → 12.4.1.jre11
  • mssql-jdbc_auth 12.2.0.x64 → 12.4.1.x86
  • nimbus-jose-jwt 9.25.6 → 9.31
  • poi-ooxml 5.2.3 → 5.2.4
  • servicediscovery 2.20.88 → 2.20.157
  • software.amazon.awssdk 2.20.157 → 2.21.41
  • tcnative-1.dll 1.2.35 → 1.2.36
  • tomcat-catalina 9.0.73 → 9.0.83
  • woodstox-core 6.5.0 → 6.5.1
  • xmlsec 3.0.1 → 3.0.2

.NET-based open source libraries have been updated:

  • Azure.Identity 1.6.1 → 1.10.4
  • Azure.Core 1.25.0 → 1.36.0

Authentication in Conversation API

Authentication for inbound conversation via Conversation API is now enforced.

CDT, Online Monitoring, and Remote Administrator page

If you are currently using one of the applications in HTTP mode, you need to enable HTTPS when upgrading to FP20.