Let the platform do the work

Sugar Serve 14.0.4 Release Notes

Overview

This document describes the changes and functionality available in Sugar 14.0.4. Sugar 14.0.4 is only available for customers on the annual upgrade path.

Fixed Issues

Sugar 14.0.4 is a security update released to address certain security vulnerabilities identified during our routine QA checks.

For customers on the annual upgrade path, we strongly recommend that you install this update at the earliest opportunity. While we have not experienced any reported incidents relating to these vulnerabilities to date, failure to install this update could leave you exposed to malicious third-party attacks. For more information, please click the link below to expand or collapse the Security Advisories.

Security Advisories

These vulnerabilities have been addressed in release 14.0.4, which is available for download from the Download Manager.

Administrators are strongly encouraged to upgrade their on-site Sugar instances running 14.0.3 or lower to version 14.0.4 to prevent potential exploitation of these weaknesses.

The following issues have been resolved in this release:

  • In certain circumstances, accessing the activity stream view from a module's list view (e.g., Cases) resulted in a 500 error. This issue has been fixed, and users can now access the Activity Stream in the module's list view as expected.
  • Repeat-type fields in Meetings did not respect the field-level permissions set for a role. The field-level permissions set for Repeat-type fields are now respected properly in Sugar.
  • Certain SugarIdentity-enabled instances experienced premature expiration of access and refresh tokens, which caused unexpected issues such as user session timeouts and HTTP errors. This issue has been resolved, and the access and refresh tokens no longer expire prematurely.

Supported Platforms

For information on supported platform components, see Sugar 14.0.x Supported Platforms.