← Back to downloads

Release notes & security

Connect Hub 4.7.0 · Revision 2 · October 5, 2026

What’s new

  • Connect Hub launchers and updated installation guides.
  • Hub connection 1.21.0 and Channel History included.
  • Channel testing tools, numeric port sorting and interface improvements.

Revision 2 updates packaging and launchers. Java libraries are unchanged from revision 1.

Built on Open Integration Engine 4.6.0, with Globalesm additions.

Security

No confirmed unpatched Critical or High findings in the October 5 review scope. One Medium file-permission issue remains open.

Early access for evaluation. This assessment is not production certification.

Review findings and limitations
Evidence, scope and open issues

Security review

Reviewed October 5, 2026 · Engine 4.7.0 revision 2 · Plugin 1.21.0

Download review summary (JSON) ↓
0confirmed unpatched
Critical / High findings

Within the reviewed scope

Artifact checks, dependency analysis and focused security tests found no confirmed unpatched Critical or High vulnerability. This is a Globalesm assessment, not an independent certification or a guarantee that no vulnerabilities exist.

One Medium issue remains open. See the finding below before installation on a shared server.

What passed

  • Authentication checks on five protected API routes, session rotation and cookie protections.
  • Nine plugin test suites and 12 focused XML, HL7, metadata and Derby regressions.
  • 881 synthetic PHI restriction checks and 12 outbound-response cases using mock output.
  • Integrity verification of 230 Administrator and extension JAR signatures, plus release checksum verification.
Open · Medium

Local file permissions

Foreground startup can create sensitive files readable by other local users when installation directories allow access. The Linux service uses a restrictive creation policy; terminal startup does not yet enforce the same policy.

For evaluation: use a dedicated account and private installation directory. Tightening terminal startup permissions remains a release action. Cross-user access was not demonstrated in the private test directory.

Why the scanner still lists 1 Critical and 4 High matches

The scan retained every match; no ignore list was applied. Review of the exact packaged bytes supports these dispositions.

Scanner matchDispositionEvidence
CVE-2022-46337
1 Critical · Derby
Backport appliedDERBY-7147 regression passed against packaged classes. Apache release notes.
CVE-2025-59250
1 High · Microsoft JDBC
Fixed artifact; version identification mismatchBundled JAR matches the official 12.10.2.jre11 download byte for byte. Microsoft release.
CVE-2024-47554
3 High · Commons IO metadata
Stale metadata in Velocity JARsThe affected class is absent from those JARs; packaged copies use Commons IO 2.21.0. Apache advisory.
Review coverage and limitations

Trivy 0.75.0 used fresh October 5 vulnerability data and identified 372 of 511 JAR paths. The 139 unidentified paths include first-party and legacy components and still need inventory coverage. A scanner match count is not a complete application security assessment.

The isolated runtime checks used macOS ARM64. Windows runtime and ACLs, other architectures, service lifecycle, the cloud Hub backend, production configuration, customer channel code and separately installed Java/OS components were outside this review. All 230 signatures passed integrity verification but use a self-signed development certificate. They do not establish a trusted production publisher.

Restrict PHI must be enabled and verified on the actual connection. Mock tests are not an end-to-end cloud data-flow audit. The setting does not contain arbitrary channel scripts or external systems. A paired staging verification with synthetic data remains pending.

Keep automatic channel deployment disabled during evaluation. Use synthetic messages and a fresh installation. The test panel suppresses connector sending; it is not a security sandbox for arbitrary scripts.