Blog

Blesta 5.10.3 Patch Released

October 22, 2024 | Posted by Paul


We are pleased to announce the released of Blesta 5.10.3, which addresses bugs discovered in the 5.10 branch. A big thanks to everyone who participated in helping to make Blesta better by reporting and confirming bugs on our forums and discord chat, we appreciate your help!

The release notes are available at https://docs.blesta.com/display/support/5.10.3.

Always run /admin/upgrade in your browser or via CLI after updating the files for your installation. Patch releases may only be applied to the minor release to which it belongs. Only apply this patch if you are running 5.10.0, 5.10.1, or 5.10.2. If you are running an earlier version, you must download the full release.

Download 5.10.3 Patch Download 5.10.3 Full

SHA256 Sum

% blesta-5.10.3.zip
46b4f10cb27304bd2fc34cf2c3c3104f1e1a4317079f0e4f004ab2f370ec48c0

% blesta-5.10.0-5.10.3.zip
18248c5d15534e68c27d0c0be7c30979eda987f2cabc75cc03eea30f297e1ed9

To patch your installation, please follow the instructions for Patching an Existing Install from our user manual.

Blesta 5.10.2 Patch Released

August 13, 2024 | Posted by Paul


We are pleased to announce the released of Blesta 5.10.2, which addresses bugs discovered in the 5.10 branch. A big thanks to everyone who participated in helping to make Blesta better by reporting and confirming bugs on our forums and discord chat, we appreciate your help!

The release notes are available at https://docs.blesta.com/display/support/5.10.2.

Always run /admin/upgrade in your browser or via CLI after updating the files for your installation. Patch releases may only be applied to the minor release to which it belongs. Only apply this patch if you are running 5.10.0, or 5.10.1. If you are running an earlier version, you must download the full release.

Download 5.10.2 Patch Download 5.10.2 Full

SHA256 Sum

% blesta-5.10.2.zip
aed831cbc4fdc97d563458ec26a209f54df22ae4f4529d9b45e18ea8ef2f2ee1

% blesta-5.10.0-5.10.2.zip
3e0309eb0be943ac29d8300462dbdba6211ac3f21b746a2d05f210a6728a0a0c

To patch your installation, please follow the instructions for Patching an Existing Install from our user manual.

Blesta 5.10.1 Patch Released

June 26, 2024 | Posted by Paul


We are pleased to announce the released of Blesta 5.10.1, which addresses bugs discovered in the 5.10 branch. A big thanks to everyone who participated in helping to make Blesta better by reporting and confirming bugs on our forums and discord chat, we appreciate your help!

The release notes are available at https://docs.blesta.com/display/support/5.10.1.

Always run /admin/upgrade in your browser or via CLI after updating the files for your installation. Patch releases may only be applied to the minor release to which it belongs. Only apply this patch if you are running 5.10.0. If you are running an earlier version, you must download the full release.

Download 5.10.1 Patch Download 5.10.1 Full

SHA256 Sum

% blesta-5.10.1.zip
3c525b62a95f8c77914d41f195e708a506887dc86b531b6b424ca2e1e091f28b

% blesta-5.10.0-5.10.1.zip
ddb24cee3e50b5b6452765e499fe0e50ed3f42505988b28ba52c76458604d612

To patch your installation, please follow the instructions for Patching an Existing Install from our user manual.

Blesta 5.9.3 Patch Released

February 21, 2024 | Posted by Paul


We are pleased to announce the released of Blesta 5.9.3, which addresses bugs discovered in the 5.9 branch. A big thanks to everyone who participated in helping to make Blesta better by reporting and confirming bugs on our forums and discord chat, we appreciate your help!

The release notes are available at https://docs.blesta.com/display/support/5.9.3.

Always run /admin/upgrade in your browser or via CLI after updating the files for your installation. Patch releases may only be applied to the minor release to which it belongs. Only apply this patch if you are running 5.9.0, 5.9.1, or 5.9.2. If you are running an earlier version, you must download the full release.

Download 5.9.3 Patch Download 5.9.3 Full

SHA256 Sum

% blesta-5.9.3.zip
bfed233dfcc2883a6c4408e1b4d8f20b771af07eb0e67dc8b8fa795dd96e68a6

% blesta-5.9.0-5.9.3.zip
a851746218377c6e9ca0be76471a8d6a7f92c8156ff9d75d53a00355f398466c

To patch your installation, please follow the instructions for Patching an Existing Install from our user manual.

Security Advisory

February 8, 2024 | Posted by Paul


Several security issues affecting Blesta versions 5.0.0 through 5.9.1 have been identified. There is no evidence to suggest that these vulnerabilities are publicly known or being exploited, but you should take action now.

A path traversal vulnerability may lead to account compromise and RCE (Remote Code Execution) through vulnerability chaining. We recommend applying the appropriate patch for your release as soon as possible, or by upgrading to version 5.9.2. Given the compounding nature of these vulnerabilies, we give this an impact rating of Critical.

More information about how we rate vulnerabilities can be found on our Security Advisories page.

Always run /admin/upgrade in your browser after patching or upgrading your installation. Patch releases may only be applied to the minor release to which it belongs, so download the appropriate patch for your minor version. If you are running a version of Blesta between 5.0 and 5.6, upgrade to 5.9.2.

Downloads

Download 5.9.2 Patch Download 5.9.2 Full

% blesta-5.9.2.zip
27f59fd3bc7a30dd6dc40ae619447fc5be049f2f3cd811ac5a6fc59b6d643b02

% blesta-5.9.0-5.9.2.zip
a4626ab2a8fe3f28010c368cc54b704cade6ac2fc299b7d48a3daec3ef9837e3

Download 5.8.3 Patch

% blesta-5.8.0-5.8.3.zip
5f5463e8590b837c76b1aa1c3f89b07e50efce477606b8f6b7f49543b2e9e828

Download 5.7.2 Patch

% blesta-5.7.0-5.7.2.zip
3f06d2a2a08f196725389e69db0cc3dc1ac05ba48f3a473b01ecc3d2caa3fa8f

To patch your installation, please follow the instructions for Patching an Existing Install from our user manual.

Resolution

  • If you are running version 5.7.x, apply the 5.7.2 patch above.
  • If you are running version 5.8.x, apply the 5.8.3 patch above.
  • If you are running version 5.9.x, apply the 5.9.2 patch above.
  • If you are running version 5.0.x through 5.6.x, upgrade to 5.9.2 Full.

Mitigation

It is best to upgrade to 5.9.2 or apply the appropriate patch. However, if you are running an affected unsupported version of Blesta (version 5.0 through 5.6), or you need more time to upgrade, you may take the following immediate steps to mitigate.

  • Visit Settings > System > General and note the location of your “Uploads Directory”.
  • Assuming your uploads directory is “/path/to/uploads/” check the directory for your company ID (typically “1”) and see if you have a “themes” directory. If the directory exists, delete the directory. Example locations for this directory are: “/path/to/uploads/1/themes”, “/path/to/uploads/2/themes”, etc. Only users with addon-companies will have any directories other than “1” within the uploads directory. Ensure “themes” is deleted from each.

If your logo dissappears, you may need to visit Settings > Company > Look and Feel > Customize and set your logo using “Set Logo URL”, not “Upload Logo”. NOTE that this may result in the “themes” directory being re-created. If you perform this step, check for and delete the “themes” directory again.

We would also highly recommend ensuring that Two-Factor Authentication is enabled for all Staff accounts. Staff can set up Two-Factor Authentication under “My Info” using a token like Google Authenticator (for iOS/Android).

Credits

These issues were reported to us by Emre Hampolat in accordance with our Responsible Disclosure Policy.