Contact Center - Patch Release Notes - Version 4.13.55
Release Details
- Release Date: 10th July 2026
- This document outlines the feature enhancements, security updates, bug fixes, and other updates included in the ECC 4.13.55 patch release.
ECC Build Versions
Component | Build URL
|
|---|---|
ameyo-server | ameyo-server-4.13.635.20260710-R\_327397-linux-gtk.x86\_64.rpm |
ameyo-art | ameyo-art-4.13.111.20260709-R\_327307-linux-gtk.x86\_64.rpm |
management-server | ameyo-management-server-3.15.128.20220819-R\_53820.x86\_64 |
management-UI | ameyo-management-server-ui-3.15.79.20220825-R\_54354.x86\_64 |
ameyo-asterisk | ameyo-asterisk13-100.0.123.20230202-R\_54429\_el7-linux-gtk.x86\_64.rpm ameyo-asterisk13-100.0.122.20230201-R\_77845\_el8.x86\_64.rpm |
ameyo-asap | ameyo-asap-100.0.19.20210708-R\_53436-linux-gtk.x86\_64.rpm ameyo-asap-100.0.31.20231212-R\_122778\_el8-linux-gtk.x86\_64.rpm |
ameyo-djinn | ameyo-djinn-100.0.411.20250115-R\_176400.x86\_64.rpm |
ameyo-codec | ameyo-codecs13-100.0.10.20180312-R\_37320.i386.rpm ameyo-codecs16-3.10.1-20150917-linux-gtk.x86\_64.rpm |
ameyo-crm | ameyocrm-100.0.379.20240516-R\_54694.x86\_64.rpm |
JDK | java-1.8.0-amazon-corretto-devel-1.8.0\_312.b07-1.x86\_64.rpm |
CAF Google Play Store | caf\_googlePlay-100.0.37.20231011-R\_112974.x86\_64.rpm |
CAF Youtube | caf\_youtube-100.8.0.20230904-R\_54528.x86\_64.rpm |
UI Less Integration - Zoho Connector laravel build | zoho-connector-100.0.40.20260707-R\_326504.x86\_64.rpm |
UI Less Integration - Zoho User Management app | zoho\_CRM\_Connector-100.0.10-R\_54327.aaex |
WFM NICE Response Transformation App | NICE\_Connector\_App-100.0.13-R\_54375.aaex |
AMF for whatsapp, cogno and Instagram integration | AMF-100.0.272.20250916-R\_54869.x86\_64.rpm |
Voicelog Privilege App | Voice\_Log\_Privilege\_App-100.0.61-R\_54105.aaex |
Dial User App | Dial\_User\_App-100.0.31-R\_51344.aaex |
System Smart View App | Smart\_User\_App-100.0.135-R\_54858.aaex |
PIck Call App | pick\_Call\_App-100.0.36-R\_51381.aaex |
Bulk Operation App | Bulk\_operation-100.0.48-R\_51285.aaex |
Desktop Notification App | NotificationApp-100.0.29-R\_52192.aaex |
Agent Signature App | Agent\_signature\_app-100.0.27-R\_51283.aaex |
Agent Self Monitoring App | Agent\_Self\_Monitoring-100.1.98-R\_51265.aaex |
Redirection App | RedirectionApp-100.0.3-R\_51489.aaex |
Quota App | quota\_management\_app-100.0.74-R\_54362.aaex |
Skill Monitoring App | skill\_monitoring\_app-100.0.14-R\_54167.aaex |
Routing Test App | RoutingTest-100.0.1-R\_54180.aaex |
Debugger App | DebuggerApp-100.0.7-R\_54338.aaex |
ACP | acp-100.1.92.20231130-R\_120901.x86\_64.rpm |
amd | ameyo-amd16-100.0.31.20210521-R\_52916-linux-gtk.i386.rpm |
zabbix | ameyo-zabbix-100.0.127.20221115-R\_63336.el7.x86\_64.rpm ameyo-zabbix-agent-100.0.54.20210617-R\_53204.x86\_64.rpm |
failover | ameyo-failover-100.0.29.20230504-R\_89111.x86\_64.rpm |
Video micro service | video-4.13.110.20240304-R\_133174.x86\_64.rpm |
Voice Agent mobile app | Android - Voice Agent App 5.7.5-R (Voice-Agent-5.7.4.20211011-release.apk) Ios - Voice Agent App 3.3 |
Field Agent mobile app | Android - Field Agent App 5.4-R (ameyo.fieldagent.com-5.4.20230905-release.apk) Ios - Field Agent App version 3.3 |
Supervisor mobile app | Android - Supervisor App : com.ameyo.supervisor-2.1.20210812-release.apk Ios - moved to live on apple store |
grafana | grafana-7.1.4-1x86\_64.rpm |
SFDC Integration app | CRM\_Integration-100.0.8-R\_54454.aaex |
Note - Releases marked in bold have changes, other releases have no change and are the same as delivered in the last patch cycle.
Security & Compliance Updates
This release includes comprehensive security hardening and vulnerability resolutions.
- PostgreSQL Password Encryption (SHA-256):
- PostgreSQL password authentication now supports SHA-256 encryption, replacing the legacy MD5 algorithm.
- This significantly improves password hashing strength, providing robust protection for database credentials against brute-force and collision attacks.
- Applies specifically to Application and Fusion on-premise setups.
- Does not apply to Video microservices or the Management Framework Architecture (MFA).
- Secure Session Management (Cookie Security):
- Addressed a security assessment (VAPT) finding where sensitive session information (such as session ID and related identifiers) could appear in the browser URL when agents open embedded applications (like Click-to-Dial in an iframe).
- A contact-center preference is now available to omit session identifiers from application URLs, preventing exposure in browser histories, bookmarks, or third-party systems.
- Enhanced HTTP Security Headers (/ameyochatjs):
- Security headers were missing on /ameyochatjs responses (HSTS and Cache-Control), as flagged in a security assessment.
- The SecurityFilter is now applied so responses include: Strict-Transport-Security (HSTS), Cache-Control, X-Content-Type-Options, X-XSS-Protection, and Referrer-Policy.
- Cross-Domain Policy Header:
- Application responses were missing the X-Permitted-Cross-Domain-Policies header.
- Support is now available via SecurityFilter and can be enabled via server configuration. When enabled, responses include X-Permitted-Cross-Domain-Policies: none, which blocks unauthorized Flash/Acrobat cross-domain policy loading.
- Permissions Policy Header:
- Application responses were missing the Permissions-Policy header.
- Support is now available via SecurityFilter and can be enabled via server configuration.
- When enabled, responses allow required browser features for same-origin use (geolocation, microphone, camera, etc.) and block unused capabilities (payment, USB, accelerometer, etc.). This reduces the attack surface while preserving WebRTC flows.
- Information Disclosure Prevention:
- Fixed an information disclosure vulnerability where HTTP 400 and 500 error responses could expose internal exception details, stack traces, and server implementation information to the browser.
- Error pages now return only generic status pages with no technical details. Full exception information is still logged server-side.
- Dependency Upgrades (jQuery):
- Upgraded the jQuery library from version 1.11.3 to 3.7.1 to address known security vulnerabilities, including Cross-Site Scripting (XSS) and prototype pollution risks associated with the older version.
- Session Token Exclusion in URLs:
- Addressed a finding where session parameters could be included in Knowledge Base and CRM iframe URLs.
- A new configuration option is available to exclude selected URL parameters from these iframe URLs. The default behavior remains unchanged for backward compatibility.
- PushListner Contract Timestamp:
- Push messages from the application server to the UI now include a server timestamp (with millisecond precision) along with the existing sequence number.
- This improves troubleshooting of timing-related issues across supported push channels (WebSocket, HTTP push, and Toolbar).
Feature Enhancements
Reporting & Analytics
- Timezone-Aware Reporting (4x):
- Reports can now completely honor your configured local timezone for both the data included and how dates/times are displayed. Previously, reports defaulted to India Standard Time (IST).
- Accurate Windows: When running a report for "Current Day" or "Last N hours/days/weeks", the time boundaries will automatically adjust to match your local timezone.
- Amplitude Analytics: Masked User IDs + Persistent Tenant Segmentation:
- Analytics events now use a masked (hashed) user identifier instead of raw user IDs.
- Tenant name and Domain are stored as persistent user properties for consistent segmentation and account-level analysis across Ameyo CCaaS, Voicebot, and Platform.
Platform & Core Infrastructure
- Open Telemetry Integration (4x):
- Zero Overhead: Monitoring is turned off initially, ensuring no extra system resource usage unless explicitly enabled.
- Customizable Ports: When enabled, the App Server exposes metrics on a dedicated network port.
- Bring Your Own Tools: Easily connect your existing monitoring stack (e.g., Prometheus, Grafana) to collect and visualize server metrics.
- Agent-Level "Voice Resource Running Mode" Configuration (4x):
- Configure voiceResourceRunningMode at the individual agent level rather than forcing a blanket configuration across the entire Contact Center.
- No CC-Wide Downtime: Mode changes can be applied dynamically without restarting the App Server.
- Canary Rollouts: Roll out the Central Registrar to a small subset of agents first.
- Isolated Rollbacks: If an issue arises, roll back only the affected agents.
- Automated Routing Configuration:
- Default Call Manager routing profiles are now created and assigned automatically to the default routing policy on application startup, simplifying inbound call routing setup.
Integrations & Toolbar
- Additional Events & Actions for Toolbar SDK:
- The Custom Toolbar SDK now supports more agent actions (login/logout, ready/not ready, hold/mute, transfer, conference, disposition, manual dial) and call events (ringing, connected, wrap-up).
- This allows building custom agent screens (CRM, custom UI, automation) without relying on internal Ameyo APIs.
- Integrations use stable public IDs only, with no dependency on internal system IDs.
- CRM HTTP-Based Authentication Scheme:
- A new, first-class authentication scheme (auth.type.general.crm.http) has been introduced to streamline CRM HTTP-based logins.
- Login requests are routed directly through the dedicated CRM HTTP path instead of defaulting to password authentication.
- Backward compatibility for existing auth.type.crm.http remains unchanged.
- Unified CRM User Mapping:
- Streamlines how administrators handle user mapping by consolidating everything into a single, unified "CRM Connectors" tab.
- Users from all enabled CRM connectors (e.g., Salesforce, Zoho) are pooled into this location.
- A dynamic filtering option appears if multiple CRMs are enabled.
- CRM PhoneBridge Integration - Mid-Call State Tracking:
- The integration now tracks and dispatches mid-call state events for complex routing, specifically blind transfers, attended (warm) transfers, and conference calls.
- This resolves issues where the CRM previously lost track of mid-call states, resulting in incomplete activity logs.
- CRM Marketplace App Review Fixes:
- Successfully addressed all review feedback from the integration team to ensure compliance with official app certification standards.
- Restored critical failure-case notifications that were missing, ensuring administrators and agents receive alerts when operations fail.
Call Recording (VLA)
- Custom Attributes in Recording File Names:
- Recording file names and VLA storage paths can now include customer-defined business identifiers (e.g., policy number, CRM record ID).
- Attributes can be pulled from Nodeflow Variables (${variableName}) or Customer/Process Data (${Customer.attribName}).
- Resolved custom attributes are persisted as JSONB data types.
- The VLA natively supports searching archived recordings directly by these custom attributes.
Bug Fixes & Stability Improvements
Telephony & Call Handling
- Concurrent Request Handling (CTIManager JobInProgress check):
- Rapid duplicate CTI requests from the same agent session (e.g., multiple "Transfer In Call" requests) could proceed concurrently and cause race conditions.
- CTIManager now checks whether an operation is already in progress for the session/agent and blocks duplicate concurrent requests, keeping flows stable.
- Deadlock Prevention in Transfer Flows (Fix lock order inversion):
- Under concurrent transfer flows, the system could deadlock because transfer dial-state verification acquired object locks in a different order than other operations.
- Lock acquisition now follows a consistent identifier-based order, preventing deadlocks.
- WebRTC Extension Switching Fix:
- When WebRTC auto-provisioned an extension, using "Change Extension" from the UI could incorrectly treat the action as a first-time selection.
- This could fail the change or leave duplicate agent entries. The flow now correctly detects an existing WebRTC extension and uses the proper change-extension path.
- UDH Calculation Accuracy (Wrap time out zero issue):
- In multi-agent transfer flows, an intermediate transfer-target agent could get wrap time recorded as 0 and an inflated talk time due to a missed 'call-leg-entered' event.
- UDH calculation now correctly treats a connected association as call-leg entered, computing times accurately.
- ReACD Call Recording Visibility:
- When an inbound call was ReACD’d (because the first agent was force-logged out), intermediate records and recordings could still appear.
- These records are now hidden by default in Supervisor Call Details, Agent Call History, and VLA Search, showing only the completed call.
Reporting & System Operations
- Complete Transfer Logs (Transfer-to-agent column blank):
- When a call was transferred to an agent who did not answer, the transfer attempt was previously missing from call reports.
- Each transfer leg (answered or unanswered) is now recorded as its own distinct entry in the call report.
- Optimized Report Extraction (Interaction report extraction delay):
- Interaction Details Report generation could take several minutes for specific date ranges due to an inefficient database query path.
- The report query now materializes remote customer data once before joining, reducing extraction time to seconds.
- SSO Login Reliability from Application UI:
- SAML and Google SSO logins from the /app/ UI could fail before authentication started due to a missing release version parameter.
- The Application UI now includes the release version in SSO requests, and the backend validates it appropriately.
- Social Media Interactions (Facebook comments not recreating):
- Social media interaction fetching could stop without error if an attachment download hung indefinitely (no network timeout).
- Downloads now use connect and read timeouts so unreachable URLs fail fast, allowing the fetcher job to continue and tickets to be created.
Browser Support
- Chrome Version: Version 149.0.7827.197 (Official Build) (arm64)