A substantial operator-facing feature and maintenance release adds new capabilities, configuration and deployment options, performance improvements, and many bug fixes. It also changes selected defaults, deprecates Token Exchange v1, and includes security and correctness fixes for authorization, identity and URL handling, SCIM, anti-phishing checks, and UMA token validation.
Action needed (6)
securitySeparate password and OTP brute force protection
Password and OTP brute force protection are now separate by default to prevent OTP bypass attacks.
security
ResourceAdminManagerURL construction validationURL construction in
ResourceAdminManageris validated against matrix parameter injection.securityClient retrieval anti-ID phishing check
Client retrieval now includes the missing anti-ID phishing check.
breaking
Zero-downtime patch releasesenabled by defaultZero-downtime patch releasesare now promoted to supported and enabled by default.breaking
--truststore-kubernetes-enabledenabled by defaultThe behavior controlled by
--truststore-kubernetes-enabledis enabled by default.breakingTen-second default not-before validation
The default not-before validation period is now 10 seconds instead of 0.
Check if affected (7)
security
Workflowsadmin permission boundariesApplies if you use
Workflows.security
Organizationslogin IdP alias disclosureApplies if you use
Organizations.securitySCIM PUT body ID override protection
Applies if you use
SCIM.- + 4 more on the release page
Plan ahead (1)
deprecatedToken Exchange v1 deprecation
Applies if you use
Token Exchange v1.