Magento is een opensource-contentmanagementplatform dat zich richt op e-commerce. Magento draait op een omgeving met Linux, Apache, MySQL en PHP. Het pakket is in twee smaken beschikbaar, namelijk Magento Open Source en Magento Commerce, die voorheen als Community Edition en Enterprise Edition bekend stonden. Voor meer informatie over dit platform verwijzen we naar deze pagina, waar wordt ingegaan op de architectuur. Versie 2.2.3 is al weer een aantal dagen beschikbaar en werd als volgt aangekondigd:
Magento Open Source 2.2.3 Release NotesWe are pleased to present Magento Commerce 2.2.3. This release includes 35 enhancements to product security, a change to the Magento Admin to support recent USPS shipping changes, and a copyright update. And thanks to our community members, it also includes enhancements to ACL control for cache management through Magento Admin.
Look for the following highlights in this release:Security enhancements
- Enhancements that help close cross-site request forgery (CSRF), unauthorized data leaks, and authenticated Admin user remote code execution vulnerabilities. See Magento Security Center for more information.
- Support for Elasticsearch 5.x. See Install and configure Elasticsearch for more information about using Elasticsearch with Magento.
- Change to Magento Admin to support recent USPS shipping changes. On February 23, 2018, USPS removed APIs that support the creation of shipping labels without postage. In response, we’ve removed this functionality from the Magento Admin. Consequently, you cannot create and print shipping labels that do not have postage applied. If you require USPS postage printing capabilities, please visit Magento Shipping to learn more, and explore various shipping extensions on Magento Marketplace.
- New layers of control for cache management tasks managed through the Magento Admin. This release introduces finer permissions for cache management tasks such as flushing cache storage, flushing the Magento cache, and refreshing cache types.
- Updated copyright to 2018.
Magento 2.2.3 includes multiple security enhancements. Although this release includes these enhancements, no confirmed attacks related to these issues have occurred to date. However, certain vulnerabilities can potentially be exploited to access customer information or take over administrator sessions, so we recommend that you upgrade your Magento software to the latest version as soon as possible. See Magento Security Center for more information.