You are viewing the documentation for Blueriq 13. Documentation for other versions is available in our documentation directory.

1. Bug fixes

Identifier

Component

Issue

Solution

BQ-13775

JAVA Runtime

CVE-2021-40690 was reported on org.apache.santuario.xmlsec which is used by the Runtime.

xmlsec is upgraded to a newer version where the reported CVE is resolved.

BQ-13549

studio

The Studio Server configured refresh tokens to only be valid for 60 minutes, causing Blueriq Encore to require logging in every hour.

The validity of refresh tokens has been extended such that users do not have to login every hour when using Encore.

2. Upgrade Instructions

There are no specific upgrade instructions for this release.

As a best practice

  • backup your repository
  • backup your database before running scripts
  • backup your spring.config.additional-location directory ([Blueriq installation directory]\Runtime)
  • backup any config files you have altered under [Blueriq installation directory]\Services

before you start the upgrade.

3. Artifacts

 The Blueriq artifacts are available under name: 13.13.6.3913

4. Aquima Libraries

There are no changes to the Aquima Libraries for this release.

5. Known issues

For an overview of known issue please refer to: Known issues

6. Libraries

ArtifactId

GroupId

License

Version in 13.13.5

Version in 13.13.6

commons-codec

commons-codec

Apache License 2.0

1.14

1.15

java-support

net.shibboleth.utilities

Apache License 2.0

7.5.1

7.5.2

joda-time

joda-time

Apache License 2.0

2.9

2.10.10

opensaml-core

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-profile-api

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-saml-api

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-saml-impl

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-security-api

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-security-impl

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-soap-api

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-xacml-api

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-xacml-impl

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-xacml-saml-api

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-xacml-saml-impl

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-xmlsec-api

org.opensaml

Apache License 2.0

3.4.5

3.4.6

opensaml-xmlsec-impl

org.opensaml

Apache License 2.0

3.4.5

3.4.6

wss4j-ws-security-common

org.apache.wss4j

Apache License 2.0

2.3.0

2.3.3

wss4j-ws-security-dom

org.apache.wss4j

Apache License 2.0

2.3.0

2.3.3

xmlsec

org.apache.santuario

Apache License 2.0

2.2.0

2.2.3