Skip to main content

Version 10.3.2.2

Release date

March 25, 2026

The release improves platform reliability and security, ensures safer access to services, mitigates high-impact injection vulnerabilities, and makes upgrades more predictable and resilient.

Corrected issues

Security

  • Fixed the vulnerabilities related to insecure third-party dependencies identified by security scanning.

  • Resolved the issue where file or directory information could be unintentionally exposed, resulting in potential data leakage.

  • Resolved the issue where Control Tower REST API endpoints were accessible without authentication through URL path manipulation.

  • Resolved the issue where stored cross-site scripting (XSS) vulnerabilities could be introduced through user-provided values, for example, dataset labels, Field Schemes, answer options, and Task Designer inputs.

  • Resolved the issue where the Workspace assignments search form rendered recent-search content in a way that enabled self-XSS.

  • Resolved the issue where a malicious XML payload in a workflow definition triggered an XML External Entity (XXE) denial-of-service condition, causing excessive resource consumption and making the affected Business Process inaccessible.

  • Resolved the issue where the HTML component in MT Builder allowed execution of malicious scripts through image element attributes, creating an XSS vulnerability.

Upgrade

  • Resolved the issue where the upgrade failed due to Keycloak startup problems.

  • Resolved the issue where Kibana login intermittently failed and dashboards did not load after the upgrade due to excessive index growth caused by data management index naming.

  • Resolved the issue where an exposed .gitignore file remained accessible after the upgrade procedure due to incomplete cleanup of web content.

  • Resolved the issue where the upgrade failed when disabling Vault certificate authentication.

  • Resolved the issue where the upgrade health check failed when LDAP was enabled because the default user was discovered incorrectly, which also caused subsequent steps (such as enabling the default user) to fail.

  • Resolved the issue where Workers failed to start because the Worker Management System (WMS) authentication failed due to legacy ZooKeeper properties not being removed during the upgrade.

  • Resolved the issue where the upgrade procedure failed in high availability (HA) environments when only one Superset host was used and elk_hosts was set to superset.

  • Resolved the issue where a database migration failed during the upgrade in environments running Microsoft SQL Server 2016.

  • Resolved the issue where Control Tower failed to start after the upgrade because a database table was incorrectly removed during migration when incomplete runs with zero completed tasks were present.

  • Resolved the issue where the upgrade failed because the nofile system limit was below the required threshold, even when the nproc limit was within the expected range.

  • Resolved the issue where the upgrade process did not correctly update the hosts.yml file with existing MinIO DNS names and the Elastic Stack (ELK) was inadvertently installed on the Superset server due to insufficient environment validation.

  • Resolved the issue where Control Tower database migrations failed due to insufficient permissions for the database user to access the required schema.

  • Resolved the issue where the S3 bucket list was not visible in the S3 UI and an internal server error was returned after the upgrade.

  • Resolved the issue where Kibana login failed with shard validation exceptions after the upgrade.

  • Resolved the issue where the health check Business Process failed with Unauthorized errors in WMS logs after the upgrade.

  • Resolved the issue where the NFS validation script failed on servers with multiple IP addresses due to incorrect unique filename assignment.

  • Resolved the issue where the upgrade failed during the database migration stage due to a Liquibase changelog checksum mismatch.

Control Tower

  • Resolved the issue where restarting Control Tower during Business Process execution caused database connection failures and related errors in event logs.

  • Resolved the issue where the Manage account page did not open in Control Tower, blocking access to user management.

  • Resolved the issue where, after restarting Control Tower, communication with a Business Process was lost for some in-progress transactions and expected output files were not produced.

  • Resolved the issue where adding a Data Store record failed with a 500 internal server error after a Field Scheme update.

  • Resolved the issue where restarting Control Tower during high-volume parent and child Business Process execution caused some synchronous call step results to be missed, leaving affected records in a submitted state even though the child Business Process completed.

  • Resolved the issue where restarting Control Tower during Evan AI Agent processing triggered duplicate task execution in certain restart and scaling scenarios.

  • Resolved the issue where some records failed to pass the join rule when Control Tower was restarted during Business Process execution, resulting in incomplete processing.

  • Resolved the issue where a custom HTML element in MT Builder failed to read input data from the data object, preventing the original document link from being generated.

  • Resolved the issue where unassigned variables were not included in the MT Builder evaluation context, restricting access to them in HTML elements and custom JavaScript components.

  • Resolved the issue where the first and last page navigation buttons were missing from the Data Store UI, which prevented users from navigating directly to the beginning or end of large datasets.

  • Resolved the issue where Control Tower sessions did not expire after the configured timeout period, allowing users to continue working past the expected session limit.

  • Resolved the issue where AutoML model synchronization failed under load, causing models to be skipped and only partially synchronized on each iteration.

  • Resolved the issue where the out-of-the-box Business Process failed at the model training step after the upgrade.

RPA

  • Resolved the issue where, after an automatic Control Tower session timeout and re-login, refreshing open Bot Manager tabs displayed an Invalid credentials error instead of re-authenticating the user.

  • Resolved the issue where process record updates in the Bot Manager Database failed in environments containing legacy duplicate records from previous fleet changes.

  • Resolved the issue where RPA failed to start after the upgrade in environments using the Unified setup due to missing changes in the bundled Java 21–compatible Manipulation Framework.

Storage

  • Resolved the issue where the Ceph S3 Manager took several minutes to load or timed out in environments with large data volumes after migration from MinIO to Ceph.

Improvements

  • Variation flavor information is now available in the task execution context for Java Native Worker and Worker Development Toolkit, enabling accurate billing and analytics event reporting.

Upgrades

  • Updated the ELK components (Kibana, Heartbeat, Metricbeat, and Filebeat) to v9.2.5 for RPA.

For details on the upgrade procedure, refer to the upgrade guides.