Bugfixes

Incident number

Summary (problem description)

Resolution

PUB-446CVE-2024-38827 was detected on spring-security-taglibsUpdated spring-security-taglibs to the latest version

CVE-2024-12798 and CVE-2024-12801 were detected on logback 1.4.14Mitigated by upgrading logback to 1.5.15

Upgrade Instructions

There are no specific upgrade instructions for this release.

3rd Party Libraries

Below is a list of changed third party libraries for this release. There is also a page available which lists all the thirrd party libraries that are used in the Publisher. See for more information: Blueriq Publisher 7 libraries.

ArtifactId

GroupId

License

Version in 7.1.3

Version in 7.1.5

antlr4-runtime

org.antlr

3-clause BSD License

4.13.0

4.10.1

byte-buddy

net.bytebuddy

Apache License 2.0

1.14.19

1.14.16

classmate

com.fasterxml

Apache License 2.0

1.6.0

1.5.1

commons-codec

commons-codec

Apache License 2.0

1.16.1

1.15

commons-lang3

org.apache.commons

Apache License 2.0

3.13.0

3.12.0

hibernate-core

org.hibernate.orm

LGPL 2.1

6.4.10.Final

6.2.25.Final

httpcore5

org.apache.httpcomponents.core5

Apache License 2.0

5.2.5

5.2.4

httpcore5-h2

org.apache.httpcomponents.core5

Apache License 2.0

5.2.5

5.2.4

jakarta.servlet.jsp.jstl-api

jakarta.servlet.jsp.jstl

Eclipse Public License - v 2.0

3.0.2

3.0.0

jandex

io.smallrye

Apache License 2.0

3.1.2

3.0.5

jcl-over-slf4j

org.slf4j

Apache License 2.0

2.0.16

2.0.13

jul-to-slf4j

org.slf4j

MIT License

2.0.16

2.0.13

log4j-api

org.apache.logging.log4j

Apache License 2.0

2.21.1

2.20.0

log4j-over-slf4j

org.slf4j

Apache License 2.0

2.0.16

2.0.13

log4j-to-slf4j

org.apache.logging.log4j

Apache License 2.0

2.21.1

2.20.0

logback-classic

ch.qos.logback

Eclipse Public License - v 1.0

1.5.15

1.4.14

logback-core

ch.qos.logback

Eclipse Public License - v 1.0

1.5.15

1.4.14

micrometer-commons

io.micrometer

Apache License 2.0

1.12.13

1.12.11

micrometer-observation

io.micrometer

Apache License 2.0

1.12.13

1.12.11

slf4j-api

org.slf4j

MIT License

2.0.16

2.0.13

spring-aop

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-beans

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-boot

org.springframework.boot

Apache License 2.0

3.2.12

3.1.12

spring-boot-autoconfigure

org.springframework.boot

Apache License 2.0

3.2.12

3.1.12

spring-boot-starter

org.springframework.boot

Apache License 2.0

3.2.12

3.1.12

spring-boot-starter-logging

org.springframework.boot

Apache License 2.0

3.2.12

3.1.12

spring-cloud-commons

org.springframework.cloud

Apache License 2.0

4.1.5

4.0.5

spring-cloud-config-client

org.springframework.cloud

Apache License 2.0

4.1.4

4.0.5

spring-cloud-context

org.springframework.cloud

Apache License 2.0

4.1.5

4.0.5

spring-cloud-starter

org.springframework.cloud

Apache License 2.0

4.1.5

4.0.5

spring-cloud-starter-bootstrap

org.springframework.cloud

Apache License 2.0

4.1.5

4.0.5

spring-cloud-starter-config

org.springframework.cloud

Apache License 2.0

4.1.4

4.0.5

spring-context

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-core

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-expression

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-hateoas

org.springframework.hateoas

Apache License 2.0

2.2.5

2.1.5

spring-jcl

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-jdbc

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-orm

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-oxm

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-security-acl

org.springframework.security

Apache License 2.0

6.2.8

6.1.9

spring-security-config

org.springframework.security

Apache License 2.0

6.2.8

6.1.9

spring-security-core

org.springframework.security

Apache License 2.0

6.2.8

6.1.9

spring-security-crypto

org.springframework.security

Apache License 2.0

6.2.8

6.1.9

spring-security-oauth2-authorization-server

org.springframework.security

Apache License 2.0

1.2.7

1.1.7

spring-security-oauth2-core

org.springframework.security

Apache License 2.0

6.2.8

6.1.9

spring-security-oauth2-jose

org.springframework.security

Apache License 2.0

6.2.8

6.1.9

spring-security-oauth2-resource-server

org.springframework.security

Apache License 2.0

6.2.8

6.1.9

spring-security-rsa

org.springframework.security

Apache License 2.0

1.1.3

1.1.1

spring-security-taglibs

org.springframework.security

Apache License 2.0

6.2.8

6.1.9

spring-security-web

org.springframework.security

Apache License 2.0

6.2.8

6.1.9

spring-tx

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-web

org.springframework

Apache License 2.0

6.1.15

6.1.14

spring-webmvc

org.springframework

Apache License 2.0

6.1.15

6.1.14