
SFTPPlus not vulnerable to Terrapin
SFTPPlus is not vulnerable to the recent SSH / SFTP Terrapin attack.
This is a subset of our news articles, filtered by tag.

SFTPPlus is not vulnerable to the recent SSH / SFTP Terrapin attack.

SFTPPlus is not using the OpenSSL 3.0.x libraries yet and is not affected by security vulnerabilities specific to these versions.

We are announcing the latest release of SFTPPlus, version 4.23.0 with improved Azure AD authentication, installers on Linux and macOS, and added XSS protection on Activity log page.

We are announcing the latest release of SFTPPlus, version 4.22.0 with support for Azure AD, updated UI and a security change in the way source IP are allowed.

We are announcing the latest release of SFTPPlus, version 4.16.0.

SFTPPlus is not using the log4j library and is not affected by any security vulnerabilities related to log4j.

We are announcing the latest release of SFTPPlus version 3.55.0.

It is common practice to secure a file transfer server using firewall rules which only allow incoming connections from trusted partners.

We are announcing the latest release of SFTPPlus version 3.39.0.

With the release of SFTPPlus 3.32.0, we have changed the default set of SSL cipher suites for the Local Manager and the HTTPS service. As with any product that runs in many environments, SFTPPlus uses a default set of SSL- related parameters that are a compromise between security and compatibility. Up to SFTPPlus version 3.31.0, we were using this highly compatible, but still reasonably secure, default set: