Vulnerability Fixes.
Bug: Nano Duration Logging bug fix.
Fix: Address vulnerabilities in partition:latest
This PR resolves vulnerabilities identified in the partition:latest image and associated Java dependencies.
Vulnerabilities Fixed:
-
io.lettuce:lettuce-core(app.jar)- Vulnerability: GHSA-q4h9-7rxj-7gx2
- Severity: Medium
- Issue: Netty vulnerability included in Redis lettuce
-
Resolution: Upgraded from
6.3.2.RELEASEto6.5.1.RELEASE.
-
io.netty:netty-common(app.jar)- Vulnerability: CVE-2024-47535
- Severity: Medium
- Issue: Denial of Service attack on Windows apps using Netty
-
Resolution: Upgraded from
4.1.109.Finalto4.1.115.
-
org.apache.tomcat.embed:tomcat-embed-core(app.jar)- Vulnerability: CVE-2024-34750
- Severity: High
- Issue: Improper Handling of Exceptional Conditions in Tomcat
-
Resolution: Upgraded from
10.1.20to10.1.25.
-
org.springframework.security:spring-security-web(app.jar)- Vulnerability: CVE-2024-38821
- Severity: Critical
- Issue: Authorization Bypass of Static Resources in Spring WebFlux Applications
-
Resolution: Upgraded from
6.2.4to6.2.7.
-
org.springframework:spring-beans(app.jar)- Vulnerability: CVE-2024-38827
- Severity: Medium
- Issue: Authorization bypass for case-sensitive comparisons in Spring Security
-
Resolution: Upgraded from
6.1.6to6.1.14.
-
org.springframework:spring-web(app.jar)- Vulnerability: CVE-2024-38809
- Severity: Medium
- Issue: DoS via conditional HTTP requests in Spring Framework
-
Resolution: Upgraded to
6.0.23.
-
org.springframework:spring-webmvc(app.jar)- Vulnerability: CVE-2024-38816
- Severity: High
- Issue: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource
-
Resolution: Upgraded to
6.1.13.
Edited by Daniel Scholl (MS]