Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Library

Old version

New version

CVEs addressed

Logback

1.2.11

1.5.3 

CVE-2023-34478

CVE-2023-6378

Jackson

2.14.12

2.17.0

CVE-2023-35116

Guava

31.1

33.2.1

CVE-2023-2976
CVE-2020-8908

Graphite metrics

4.2.7

4.2.25

CVE-2023-46120

Zookeper

3.6.3

3.9.2

CVE-2023-44981
CVE-2024-23944

Shiro

1.11.0

1.13.0

CVE-2023-46749
CVE-2023-46750

JSON

20230227

20240303

CVE-2023-5072

SnakeYaml

1.33

2.2

CVE-2022-1471

Netty

4.1.87.Final

4.1.110.Final

CVE-2023-44487
CVE-2023-34462
CVE-2024-29025

Jetty

9.4.48

9.4.54

CVE-2023-36478
CVE-2023-44487
CVE-2023-26048
CVE-2023-26049
CVE-2023-40167
CVE-2023-36479
CVE-2023-41900

ElasticSearch

7.17.1

7.17.21

CVE-2023-46674
CVE-2023-31418
CVE-2023-31419
CVE-2023-46673

Spring Web5.3.275.3.36CVE-2024-22262
CVE-2024-22259
CVE-2024-22243
Nimbus JOSE+JWT9.319.40CVE-2023-52428
CVE-2024-30172
CVE-2024-30171
CVE-2024-29857
CVE-2023-51775
CVE-2023-33202
CVE-2023-33201
CVE-2023-31582
Bouncy Castle Provider1.701.78.1CVE-2024-30172
CVE-2024-30171
CVE-2024-29857
CVE-2023-33202
CVE-2023-33201

Other Vulnerabilities

NameCVE addressedRemediation
Teamwork Cloud / Magic Collaboration StudioCVE-2023-3589

To enable CSRF protection, you need to uncomment esi.dm.csrf.allowed-addresses property in the Teamwork Cloud application.conf file.

esi.dm {

    # Enable to turn on CSRF protection. This will block all incoming REST API requests, except those, coming from specified

    # IP addresses. List of strings, allowed IP must begin with specified string.

    # csrf.allowed-addresses = ["127.0.0.1", "0.0.0"]

}

Cameo Simulation Toolkit / Magic Model Analyst

...