Open Source components have been updated, as listed below, to address known software vulnerabilities. Legal Notices will be updated to reflect these, and other changes, at the next scheduled regular release.
Teamwork Cloud/Magic Collaboration Studio
Library | Old version | New version | CVEs addressed |
BouncyCastle provider | 1.56 | 1.70 | |
Eclipse EMF common | 2.30.0 | 2.31.0 | |
Eclipse EMF ecore | 2.36.0 | 2.37.0 | |
Eclipse EMF xmi | 2.37.0 | 2.38.0 | |
Jetty | 9.4.54.v20240208 | 9.4.56.v20240826 | |
Netty | 4.1.107.Final | 4.1.112.Final | CVE-2024-29025 |
ElasticSearch | 7.17.18 | 7.17.24 | CVE-2024-23450 |
Cameo Simulation Toolkit / Magic Model Analyst
Library | Old version | New version | CVEs addressed |
jfreechart | 1.5.3 | 1.5.5 | |
Jetty | 9.4.54.v20240208 | 9.4.56.v20240826 | CVE-2024-6763, CVE-2024-8184 |
Cameo DataHub
Library | Old Version | New version | CVEs addressed |
h2 | 2.2.224 | 2.3.232 | CVE-2018-14335 |
velocity-engine-core | 2.3 | 2.4 | CVE-2024-47554 |
WebApps
Library | Old version | New version | CVEs addressed |
ASM | 9.5 | 9.7 | |
Angus Email | 2.0.2 | 2.0.3 | |
SLF4J API | 2.0.12 | 2.0.16 | |
Spring Framework | 6.0.18 | 6.0.23 | |
Apache HttpComponents Core HTTP/1.1 | 5.2.4 | 5.2.5 | |
Jacoco Maven Plugin | 0.8.10 | 0.8.12 | |
AspectJ Weaver | 1.9.21.1 | 1.9.21.2 | |
Jakarta Activation API | 2.1.2 | 2.1.3 | |
Byte Buddy | 1.14.12 | 1.14.19 | |
Apache Log4j | 2.23.0 | 2.23.1 | - |
bcpkix-jdk18on, bcprov-jdk18on, bcutil-jdk18on | 1.77 | 1.78.1 | CVE-2024-29857 CVE-2024-30171 CVE-2024-30172 CVE-2024-34447 |
java-support | 8.4.0 | 8.4.2 | CVE-2024-22262 CVE-2024-22259 CVE-2024-22243 CVE-2023-6378 |
commons-codec | 1.16.1 | 1.17.1 | - |
commons-io | 2.15.1 | 2.17.0 | - |
commons-validator | 1.7 | 1.9.0 | CVE-2020-15250 |
micrometer-commons, micrometer-observation | 1.12.4 | 1.12.9 | - |
Spring Security | 6.2.3 | 6.2.6 | CVE-2024-38809 CVE-2024-22262 |
OpenSAML | 4.3.0 | 4.3.2 | CVE-2024-22262 CVE-2024-22259 CVE-2024-22243 CVE-2023-44483 |
XmlBeans | 5.2.0 | 5.2.1 | - |
XML APIs | - | 1.4.01 | - |