You are viewing the documentation for Blueriq 14. Documentation for other versions is available in our documentation directory.

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

1. Upgrade Instructions

There are no specific upgrade instructions for this release.

As a best practice

  • backup your repository
  • backup your database before running scripts
  • backup your spring.config.additional-location directory ([Blueriq installation directory]\Runtime)
  • backup any config files you have altered under [Blueriq installation directory]\Services

before you start the upgrade.

2. Artifacts

 The Blueriq artifacts are available under name:  14.11.1.4963

This release includes these versions of Blueriq components with a separate life cycle:

Component

Version

Customer Data Service3.4.12
DCM Lists Service2.0.4
Material Theme1.0.44
Development tools frontend1.1.3

3. Aquima Libraries

There are no specific Library updates for this release.

4. Libraries

In this release, the set of third party libraries that is used by Blueriq was updated. When your installation of Blueriq includes custom components (artifacts that do not ship with Blueriq, such as proprietary plugins), those components should be tested for compatibility with these changes.

ArtifactId

GroupId

License

Version in 14.10.2

Version in 14.11.0

javassist

org.javassist

Apache License 2.0

3.27.0-GA

(error)

org.eclipse.jgit.ssh.jsch

org.eclipse.jgit

EDL

(error)

5.12.0.202106070339-r

amqp-client

com.rabbitmq

Apache License 2.0

5.12.0

5.13.1

brave

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-context-slf4j

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-http

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-httpasyncclient

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-httpclient

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-jms

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-kafka-clients

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-kafka-streams

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-messaging

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-mongodb

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-rpc

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-spring-rabbit

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

brave-instrumentation-spring-web

io.zipkin.brave

Apache License 2.0

5.13.2

5.13.7

bson

org.mongodb

Apache License 2.0

4.2.3

4.4.2

byte-buddy

net.bytebuddy

Apache License 2.0

1.11.12

1.12.8

classgraph

io.github.classgraph

MIT License

4.8.69

4.8.108

commons-dbcp2

org.apache.commons

Apache License 2.0

2.8.0

2.9.0

commons-pool2

org.apache.commons

Apache License 2.0

2.9.0

2.11.1

hibernate-core

org.hibernate

LGPL 2.1

5.4.33

5.6.7.Final

hibernate-entitymanager

org.hibernate

LGPL 2.1

5.4.33

5.6.7.Final

jackson-databind

com.fasterxml.jackson.core

Apache License 2.0

2.13.2.1

2.13.2.2

jandex

org.jboss

Apache License 2.0

2.2.3.Final

2.4.2.Final

JavaEWAH

com.googlecode.javaewah

Apache License 2.0

1.1.6

1.1.7

jedis

redis.clients

MIT License

3.6.3

3.7.1

metrics-core

io.dropwizard.metrics

Apache License 2.0

4.1.31

4.2.9

micrometer-core

io.micrometer

Apache License 2.0

1.7.10

1.8.4

mongodb-driver-core

org.mongodb

Apache License 2.0

4.2.3

4.4.2

mongodb-driver-sync

org.mongodb

Apache License 2.0

4.2.3

4.4.2

nimbus-jose-jwt

com.nimbusds

Apache License 2.0

9.10.1

9.14

oauth2-oidc-sdk

com.nimbusds

Apache License 2.0

9.9.1

9.19

org.eclipse.jgit

org.eclipse.jgit

EDL

5.1.3.201810200350-r

5.12.0.202106070339-r

org.eclipse.jgit.http.apache

org.eclipse.jgit

EDL

5.1.3.201810200350-r

5.12.0.202106070339-r

spring-amqp

org.springframework.amqp

Apache License 2.0

2.3.15

2.4.3

spring-boot

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-boot-actuator

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-boot-actuator-autoconfigure

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-boot-autoconfigure

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-boot-configuration-processor

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-boot-starter

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-boot-starter-aop

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-boot-starter-data-mongodb

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-boot-starter-logging

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-boot-starter-validation

org.springframework.boot

Apache License 2.0

2.5.12

2.6.6

spring-cloud-commons

org.springframework.cloud

Apache License 2.0

3.0.5

3.1.1

spring-cloud-config-client

org.springframework.cloud

Apache License 2.0

3.0.6

3.1.1

spring-cloud-config-server

org.springframework.cloud

Apache License 2.0

3.0.6

3.1.1

spring-cloud-context

org.springframework.cloud

Apache License 2.0

3.0.5

3.1.1

spring-cloud-sleuth-api

org.springframework.cloud

Apache License 2.0

3.0.5

3.1.1

spring-cloud-sleuth-autoconfigure

org.springframework.cloud

Apache License 2.0

3.0.5

3.1.1

spring-cloud-sleuth-brave

org.springframework.cloud

Apache License 2.0

3.0.5

3.1.1

spring-cloud-sleuth-instrumentation

org.springframework.cloud

Apache License 2.0

3.0.5

3.1.1

spring-cloud-starter

org.springframework.cloud

Apache License 2.0

3.0.5

3.1.1

spring-cloud-starter-bootstrap

org.springframework.cloud

Apache License 2.0

3.0.5

3.1.1

spring-cloud-starter-config

org.springframework.cloud

Apache License 2.0

3.0.6

3.1.1

spring-cloud-starter-sleuth

org.springframework.cloud

Apache License 2.0

3.0.5

3.1.1

spring-data-commons

org.springframework.data

Apache License 2.0

2.5.10

2.6.3

spring-data-keyvalue

org.springframework.data

Apache License 2.0

2.5.10

2.6.3

spring-data-mongodb

org.springframework.data

Apache License 2.0

3.2.10

3.3.3

spring-data-redis

org.springframework.data

Apache License 2.0

2.5.10

2.6.3

spring-hateoas

org.springframework.hateoas

Apache License 2.0

1.3.7

1.4.1

spring-rabbit

org.springframework.amqp

Apache License 2.0

2.3.15

2.4.3

spring-security-config

org.springframework.security

Apache License 2.0

5.5.5

5.6.2

spring-security-core

org.springframework.security

Apache License 2.0

5.5.5

5.6.2

spring-security-crypto

org.springframework.security

Apache License 2.0

5.5.5

5.6.2

spring-security-ldap

org.springframework.security

Apache License 2.0

5.5.5

5.6.2

spring-security-oauth2-client

org.springframework.security

Apache License 2.0

5.5.5

5.6.2

spring-security-oauth2-core

org.springframework.security

Apache License 2.0

5.5.5

5.6.2

spring-security-web

org.springframework.security

Apache License 2.0

5.5.5

5.6.2

spring-session-core

org.springframework.session

Apache License 2.0

2.5.5

2.6.2

spring-session-data-redis

org.springframework.session

Apache License 2.0

2.5.5

2.6.2

zipkin

io.zipkin.zipkin2

Apache License 2.0

2.23.0

2.23.2

zipkin-reporter

io.zipkin.reporter2

Apache License 2.0

2.16.1

2.16.3

zipkin-reporter-brave

io.zipkin.reporter2

Apache License 2.0

2.16.1

2.16.3

zipkin-reporter-metrics-micrometer

io.zipkin.reporter2

Apache License 2.0

2.16.1

2.16.3






5. Retirement announcement

There are no specific retirement announcements.

For a full list of deprecated features, go to Deprecated features.

6. Bug fixes

Identifier

Component

Issue

Solution

BQ-15778

Runtime, Customerdata, DCM Lists

CVE-2022-22968 is a follow up CVE from CVE-2022-22965. The issue is caused by the disallowedFields property in a DataBinder being case sensitive which means a field was not effectively protected unless patterns were registered with both upper and lower case for the first character of the field, including all combinations of upper and lower case for the first character of all nested fields within the property path.

Upgraded spring-framework to the version where this issue is fixed.

7. Known issues

For an overview of known issue please refer to: Known issues

  • No labels