This is an automated email from the ASF dual-hosted git repository.
ffang pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/cxf.git
The following commit(s) were added to refs/heads/main by this push:
new 27e15770c0c update CXF 4.2.4 release notes
27e15770c0c is described below
commit 27e15770c0c3f1ae79a853b2c05cbb85e91e4c32
Author: Freeman Fang <[email protected]>
AuthorDate: Thu Oct 1 11:59:37 2026 -0400
update CXF 4.2.4 release notes
---
distribution/src/main/release/release_notes.txt | 29 +++++++++++--------------
1 file changed, 13 insertions(+), 16 deletions(-)
diff --git a/distribution/src/main/release/release_notes.txt
b/distribution/src/main/release/release_notes.txt
index 01abe24bdbe..41a75c6d8e0 100644
--- a/distribution/src/main/release/release_notes.txt
+++ b/distribution/src/main/release/release_notes.txt
@@ -1,4 +1,4 @@
-Apache CXF 4.2.3 Release Notes
+Apache CXF 4.2.4 Release Notes
1. Overview
@@ -36,7 +36,7 @@ for further information and requirements for upgrading from
earlier
versions of CXF.
-4.2.3 fixes over 10 JIRA issues reported by users and the community.
+4.2.4 fixes over 8 JIRA issues reported by users and the community.
2. Installation Prerequisites
@@ -78,20 +78,17 @@ for caveats when upgrading.
7. Specific issues, features, and improvements fixed in this version
-** Sub-task
- * [CXF-9229] - Prove that CXF can support Post-Quantum Cryptography TLS
using the X25519MLKEM768 hybrid key-encapsulation mechanism (KEM).
+** Bug
+ * [CXF-9032] - JWK keystore type is not getting loaded if JWT contains x5t
header
+ * [CXF-9234] - Concurrent DynamicClientFactory.createClient for the same
WSDL url corrupts the cached schema DOM and spins forever at 100% CPU
+ * [CXF-9235] - Invocation.Builder.property() settings ignored by HTTP
transport for set.content.type.for.empty.request
+ * [CXF-9240] - OAuthJSONProvider.appendJsonPair() does not escape JSON
string values — output injection / malformed JSON in introspect & token
responses
+ * [CXF-9241] - ImplicitConfidentialGrantService violates RFC 6749 §4.2.2
by issuing Refresh Tokens in the Implicit Flow
+ * [CXF-9245] - Race Condition in ServerLifeCycleManagerImpl#stopServer()
+ * [CXF-9250] - HttpClientHTTPConduit: failed exchange without request body
is re-sent endlessly from the exceptionally callback (e.g. remote WSDL fetch)
-** Bug
- * [CXF-9161] - Some of the OIDCFlowTest fail with timeout (JPA only) when
HttpClient instance is shared
- * [CXF-9219] - cxf-bom manages dependencies for 4.x that no longer exist
or are not published
- * [CXF-9221] - JCache providers use inverted isExpired() logic causing
expired tokens/codes to never be evicted
- * [CXF-9222] - partialMatchScopeValidation allows prefix-based scope
escalation (e.g., read grants readwrite)
- * [CXF-9223] - completeAudienceMatch=false defaults to prefix matching for
audience validation, widening resource access
- * [CXF-9225] - OIDC RP does not enforce nonce validation for
Implicit/Hybrid flows
- * [CXF-9226] - Proxy authentication fails with IllegalStateException
instead of HTTPException (407)
- * [CXF-9227] - CXF 4.1.7 regression: more SecurityManager permission
requirements
-
-** Task
- * [CXF-9230] - Update to Spring Boot 4.1 release line
+
+** Improvement
+ * [CXF-9233] - AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in
the message properties, so RESP_OUT log is disable :(