# 3.8.0 * Feature #36645: Change the default Foreman Redis cache DB to 4 * Feature #36573: Reuse foreman_proxy::foreman_base_url value for puppet::server_foreman_url * Bug #36759: CVE-2022-3874: OS command injection via ct_command and fcct_command * Bug #36760: CVE-2023-4886: World readable tomcat server.xml contains passwords * Bug #36796: Some events are not visible even being triggered * Bug #36768: CVE-2022-4130: Blind SSRF via Referer header * Bug #36709: Set ANSIBLE_PERMISSION_CLASSES as empty list to allow syncing collection repos on capsule without RBAC access to Galaxy endpoints * Feature #36694: Show failed resources in failed installation report * Bug #36812: allow setting (fc)ct_location * Feature #36697: Expose candlepin logging parameter in the installer * Feature #36784: Drop Apache mpm_event MaxRequestPerChild values from tuning profiles * Bug #36791: Typo in variable name in form for taxonomies