You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Current »

Bugfixes

Incident number

Summary (problem description)

Resolution

PUB-444CVE-2024-38816, CVE-2024-38820 and CVE-2024-38821  was detected on spring framework 6.1.12Updated spring framework to latest version

Upgrade Instructions

There are no specific upgrade instructions but when you upgrade from version 8.0.1, please take a look at the Publisher 8.0 Upgrade Instructions

3rd Party Libraries

There is a page available which lists all the 3rd party libraries that are used in the Publisher. See for more information: Blueriq Publisher 8 libraries.

ArtifactId

GroupId

License

Version in 8.0.1

Version in 8.0.2

byte-buddy

net.bytebuddy

Apache License 2.0

1.14.13

1.14.19

classmate

com.fasterxml

Apache License 2.0

1.6.0

1.7.0

hibernate-core

org.hibernate.orm

LGPL 2.1

6.4.4.Final

6.5.3.Final

httpclient5

org.apache.httpcomponents.client5

Apache License 2.0

5.2.3

5.3.1

httpcore5

org.apache.httpcomponents.core5

Apache License 2.0

5.2.4

5.2.5

httpcore5-h2

org.apache.httpcomponents.core5

Apache License 2.0

5.2.4

5.2.5

jackson-annotations

com.fasterxml.jackson.core

Apache License 2.0

2.17.0

2.17.2

jackson-core

com.fasterxml.jackson.core

Apache License 2.0

2.17.0

2.17.2

jackson-databind

com.fasterxml.jackson.core

Apache License 2.0

2.17.0

2.17.2

jackson-dataformat-yaml

com.fasterxml.jackson.dataformat

Apache License 2.0

2.17.0

2.17.2

jackson-datatype-jsr310

com.fasterxml.jackson.datatype

Apache License 2.0

2.17.0

2.17.2

jakarta.servlet.jsp.jstl-api

jakarta.servlet.jsp.jstl

Eclipse Public License - v 2.0

3.0.0

3.0.2

jakarta.xml.soap-api

jakarta.xml.soap

Eclipse Public License - v 1.0

3.0.1

3.0.2

jakarta.xml.ws-api

jakarta.xml.ws

Eclipse Public License - v 1.0

4.0.1

4.0.2

jcl-over-slf4j

org.slf4j

Apache License 2.0

2.0.13

2.0.16

jul-to-slf4j

org.slf4j

MIT License

2.0.13

2.0.16

log4j-api

org.apache.logging.log4j

Apache License 2.0

2.21.1

2.23.1

log4j-over-slf4j

org.slf4j

Apache License 2.0

2.0.13

2.0.16

log4j-to-slf4j

org.apache.logging.log4j

Apache License 2.0

2.21.1

2.23.1

logback-classic

ch.qos.logback

Eclipse Public License - v 1.0

1.4.14

1.5.11

logback-core

ch.qos.logback

Eclipse Public License - v 1.0

1.4.14

1.5.11

micrometer-commons

io.micrometer

Apache License 2.0

1.12.9

1.13.6

micrometer-observation

io.micrometer

Apache License 2.0

1.12.9

1.13.6

nimbus-jose-jwt

com.nimbusds

Apache License 2.0

9.39.1

9.39.3

saaj-impl

com.sun.xml.messaging.saaj

Eclipse Public License - v 1.0

3.0.3

3.0.4

slf4j-api

org.slf4j

MIT License

2.0.13

2.0.16

spring-aop

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-beans

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-boot

org.springframework.boot

Apache License 2.0

3.2.5

3.3.5

spring-boot-autoconfigure

org.springframework.boot

Apache License 2.0

3.2.5

3.3.5

spring-boot-starter

org.springframework.boot

Apache License 2.0

3.2.5

3.3.5

spring-boot-starter-logging

org.springframework.boot

Apache License 2.0

3.2.5

3.3.5

spring-cloud-commons

org.springframework.cloud

Apache License 2.0

4.1.2

4.1.4

spring-cloud-config-client

org.springframework.cloud

Apache License 2.0

4.1.1

4.1.3

spring-cloud-context

org.springframework.cloud

Apache License 2.0

4.1.2

4.1.4

spring-cloud-starter

org.springframework.cloud

Apache License 2.0

4.1.2

4.1.4

spring-cloud-starter-bootstrap

org.springframework.cloud

Apache License 2.0

4.1.2

4.1.4

spring-cloud-starter-config

org.springframework.cloud

Apache License 2.0

4.1.1

4.1.3

spring-context

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-core

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-expression

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-hateoas

org.springframework.hateoas

Apache License 2.0

2.2.2

2.3.3

spring-jcl

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-jdbc

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-orm

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-oxm

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-security-acl

org.springframework.security

Apache License 2.0

6.2.4

6.3.4

spring-security-config

org.springframework.security

Apache License 2.0

6.2.4

6.3.4

spring-security-core

org.springframework.security

Apache License 2.0

6.2.4

6.3.4

spring-security-crypto

org.springframework.security

Apache License 2.0

6.2.4

6.3.4

spring-security-oauth2-authorization-server

org.springframework.security

Apache License 2.0

1.2.4

1.3.3

spring-security-oauth2-core

org.springframework.security

Apache License 2.0

6.2.4

6.3.4

spring-security-oauth2-jose

org.springframework.security

Apache License 2.0

6.2.4

6.3.4

spring-security-oauth2-resource-server

org.springframework.security

Apache License 2.0

6.2.4

6.3.4

spring-security-rsa

org.springframework.security

Apache License 2.0

1.1.2

1.1.3

spring-security-taglibs

org.springframework.security

Apache License 2.0

6.2.4

6.3.4

spring-security-web

org.springframework.security

Apache License 2.0

6.2.4

6.3.4

spring-tx

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-web

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-webmvc

org.springframework

Apache License 2.0

6.1.12

6.1.14

spring-ws-core

org.springframework.ws

Apache License 2.0

4.0.10

4.0.11

spring-xml

org.springframework.ws

Apache License 2.0

4.0.10

4.0.11

  • No labels