The following issues were fixed in MOVEit Gateway 2024.

ID

Category

Known Issue

8213

Security

The XML parser is configured to disable external entity resolution.

76909

Security

The json-path version was updated to address CVE-2023-51074.

76320, 76321

Security

The Logback Core Module version was updated to address CVE-2023-6378.

29897

Security

The Jetty version is not returned in the HTTP responses.

5688

Security

Dependencies and attributes were updated to prevent potential Cross-Site Request Forgery (CSRF) attacks.

78728, 78122

Security

The Spring Web version was updated to address CVE-2024-22259 and CVE-2024-22243.

77013

SFTP

Canceled SFTP transfers do not disrupt SFTP and FTPS traffic when using Gateway.

78700

Security

The spring-security-core version was updated to address CVE-2024-22257.