Open Source components have been updated, as listed below, to address known software vulnerabilities. Legal Notices will be updated to reflect these, and other changes, at the next scheduled regular release. 

Teamwork Cloud/Magic Collaboration Studio

Library

Old version

New version

CVEs addressed

Eclipse EMF common2.30.02.31.0
Eclipse EMF ecore2.36.02.37.0
Eclipse EMF xmi2.37.02.38.0
Jetty9.4.54.v202402089.4.56.v20240826
Netty4.1.108.Final4.1.114.FinalCVE-2024-29025
ElasticSearch7.17.207.17.24CVE-2024-23450

Cameo Simulation Toolkit / Magic Model Analyst


Library

Old version

New version

CVEs addressed

jfreechart1.5.31.5.5
Jetty9.4.54.v202402089.4.56.v20240826CVE-2024-6763, CVE-2024-8184

WebApps

Library

Old version

New version

CVEs addressed

commons-codec1.16.11.17.1-
commons-io2.16.02.17.0-
java-support8.4.08.4.2

CVE-2024-22262

CVE-2024-22259

CVE-2024-22243

CVE-2023-6378

Micrometer1.12.51.12.9-
OpenSAML4.3.04.3.2

CVE-2024-22262

CVE-2024-22259

CVE-2024-22243

CVE-2023-44483

Spring Expression Language (SpEL)6.1.66.1.13-
Spring Transaction6.1.66.1.13-
Spring Security6.2.46.3.3CVE-2024-38809
RoaringBitmap1.0.51.0.6-
XMLBeans5.2.05.2.1-
XML APIs-1.4.01-
Byte Buddy1.14.121.14.19
bcpkix-jdk18on, bcprov-jdk18on, bcutil-jdk18on1.771.78.1

CVE-2024-29857

CVE-2024-30171

CVE-2024-30172

CVE-2024-34447

Jakarta Activation API2.1.22.1.3
XML APIs-1.4.01-
Apache HttpComponents Core HTTP/1.15.2.45.2.5
Jacoco Maven Plugin0.8.110.8.12
Spring Framework6.1.66.1.13
SLF4J API2.0.132.0.16
Angus Email2.0.22.0.3
Netty4.1.108.Final4.1.113.Final

Modeling tools

Library

Old version

New version

CVEs addressed

jxbrowser7.37.27.41.2