- Resolved numerous bugs including locked‑user re‑enable attribute loss, Remember‑Me with external Infinispan, WebAuthn login flow errors, hostname path restrictions, admin client @NoCache annotation, realm import default ACR handling, LDA...
- Patched critical security issues CVE‑2024‑8883 (open redirect via redirect URI validation) and CVE‑2024‑8698 (improper SAML response verification leading to privilege escalation).