Updated 3/31/2016
We are releasing Magento Enterprise Edition and Community Edition 2.0.4 to address a packaging issue with yesterday’s release. If you have already installed the original release, you must replace it with the new version to ensure that your site receives all security enhancements. You can download Magento Enterprise Edition and Community Edition 2.0.4 from the distribution channels listed below. We apologize for the inconvenience this may cause and we are reviewing our processes to prevent this from happening in the future.
====
Today, we are making a new upgrade available that improves the security and functionality of Magento 2.0 sites. The new release, Magento 2.0.3, is available for both Magento Enterprise Edition and Community Edition, and contains several security improvements, including:
In addition, Magento 2.0.3 includes performance improvements and functional enhancements to the Orders API, Google Tag Manager, permissions, and other areas. Full details on the functional enhancements are included in the release notes for Enterprise Edition and Community Edition; more information on the security updates can be found on the Magento Security Center.
Merchants are strongly advised to deploy this new release. Magento 2.0.3 can be downloaded from the following locations:
Enterprise Edition 2.0.3 (New .zip file installations) |
Partner Portal > Downloads > Magento Enterprise Edition 2.X > Magento Enterprise Edition 2.x Release > Version 2.0.3 |
Enterprise Edition 2.0.3 (New composer installations) |
http://devdocs.magento.com/guides/v2.0/install-gde/prereq/integrator_install.html |
Enterprise Edition 2.0.3 (Composer upgrades) |
http://devdocs.magento.com/guides/v2.0/comp-mgr/bk-compman-upgrade-guide.html |
Enterprise Edition 2.0.3 (New .zip file installations) |
My Account > Downloads > Magento Enterprise Edition 2.X > Magento Enterprise Edition 2.x Release > Version 2.0.3 |
Enterprise Edition 2.0.3 (New composer installations) |
http://devdocs.magento.com/guides/v2.0/install-gde/prereq/integrator_install.html |
Enterprise Edition 2.0.3 (Composer upgrades) |
http://devdocs.magento.com/guides/v2.0/comp-mgr/bk-compman-upgrade-guide.html |
Community Edition 2.0.3 (New .zip file installations) |
Community Edition Download Page > Download Tab
|
Community Edition 2.0.3 (New composer installations) |
http://devdocs.magento.com/guides/v2.0/install-gde/prereq/integrator_install.html |
Community Edition 2.0.3 (Composer upgrades) |
http://devdocs.magento.com/guides/v2.0/comp-mgr/bk-compman-upgrade-guide.html |
Community Edition 2.0.3 (Developers contributing to the CE code base) |
http://devdocs.magento.com/guides/v2.0/install-gde/install/cli/dev_options.html |
If you have not previously upgraded to Magento Enterprise Edition or Community Edition 2.0.2, you should review the upgrade information posted on our Security Center as there are some additional steps you may need to take.
POTENTIAL VULNERABILITY
We’d also like to highlight an article just posted on our Security Center that shares best practices for protecting stores from brute-force password guessing attacks. We’ve been made aware of a recent rise in these attacks, so it is critical for merchants to take these important steps to reduce their risk. We strongly recommend that you review the best practices outlined in this article with your Solution and Hosting Partners immediately and implement the ones that are best suited to your unique situation.
Thank you for your prompt attention to these issues.