Skip to content

Releases: cloudogu/cas

v7.2.7-5

26 Nov 07:34

Choose a tag to compare

Changed

  • [#306] Updated default settings for java heap size, memory request and memory limit.

v7.2.7-4

27 Oct 08:10

Choose a tag to compare

Changed

  • [#301] - Added pruning script to avoid conflicting versions in final WAR

Fixed

  • [#297] make ldap an optional dependency again and avoid a failing CAS upgrade
    • This change reverts #290 in version 7.2.6-3 from 2025-09-18 and makes external directory configurations a first-class
      citizen again.
    • As in a CES VM the directory configuration is implemented in such an integral part that an additional LDAP dogu
      installation would lead to an unhealthy dogu on a regular basis. Unhealthy dogus are set to

v7.2.7-3

23 Oct 17:17

Choose a tag to compare

Changed

  • [#299] - Fixed mixed version of Spring in final WAR

v7.2.7-2

17 Oct 15:03

Choose a tag to compare

Changed

  • [#295] - Upgraded Spring Boot to v3.4.6

Security

  • [#295] Fix CVE-2025-41232 - Fixed a Spring Security issue that could allow unauthorized access.

v7.2.7-1

06 Oct 10:23

Choose a tag to compare

Caution

Security Advisory
CAS instances acting as an OAuth/OIDC provider are affected by a vulnerability in earlier releases.
Use 7.2.7 or newer (or 7.1.6.2 on 7.1.x).
See Apereo CAS Advisory (2025-09-25) for details.

Changed

  • [#293] Upgraded CAS to 7.2.7

v7.2.6-3

18 Sep 13:45

Choose a tag to compare

Changed

  • [#290] make ldap a non-optional dependency to avoid not having a ldap-service-account when dogus are installed in a wrong order
    • If an external ldap should be used, this can be configured, but the internal ldap-dogu must be installed

v7.2.6-2

10 Sep 07:19

Choose a tag to compare

Changed

  • [#283] Upgraded log4j to 2.24.3
  • [#283] Upgraded tomcat to 10.1.43
  • [#283] Integrated pipe-build-lib
  • [#284] Added oidc/platform login integrationtests

Fixed

  • [#284] Fixed OIDC Platform Login
  • [#283] Log4j Version mismatch on MN
  • [#283] removed deprecated javax references
  • [#286] Fixed principal name shown in navigation bars of dogus

v7.2.6-1

26 Aug 11:26

Choose a tag to compare

Changed

  • [#279] Changed Jenkins-Build to be able to start the integration tests more reliably
  • [#281] Upgraded CAS to 7.2.6
  • [#281] Upgraded Sprint Boot to 3.4.4

v7.1.6-6

14 Aug 14:16

Choose a tag to compare

Fixed

  • [#276] Fix typo in cas configuration

v7.1.6-5

14 Aug 05:22

Choose a tag to compare

Fixed

  • [#273] Remove expired sessions that stay active by configuring an interval-based registry cleaner