Bugfixes

Incident number
Summary (problem description)
Resolution
PUB-166

The publisher dependency checker identified CVE-2018-15758 in third party libraries.

Upgraded spring-security-oauth2 from version 2.3.3 to 2.3.4 to resolve this vulnerability.

PUB-167The publisher dependency checker identified CVE-2018-1000632 in third party libraries.Upgraded dom4j from version 1.6.1 to 2.1.1 to resolve this vulnerability.

Upgrade Instructions

There are no upgrade instructions.

3rd Party Libraries

There is also a page available which lists all the 3rd party libraries that are used in the Publisher. See for more information: Blueriq Publisher 4 libraries. For a list of all known vulnerabilities please view Blueriq Publisher Vulnerabilities