Move os-core-common-spring6 to os-core-common (latest)
Changes
- Updated
os-core-commonversion from0.26.0-rc2to3.3.0 - Updated
json-smartversion from2.5.1to2.5.2 - Updated
core-lib-azureversion from2.0.3to2.0.4 - Updated
os-core-lib-ibmversion from0.26.0-rc8to0.27.0-rc3 - Changed dependency
os-core-common-spring6toos-core-common - Updated test case
AuthorizationServiceForServiceAdminImplTestto useJWTClaimsSetandJWSObjectinstead ofJws<Claims>
Security Impact
New Vulnerabilities
High Severity
-
CVE-2025-24970 (pom): Vulnerability in
io.netty:netty-handlerversion4.1.114.FinalwhereSslHandlerdoesn't correctly validate packets, leading to potential native crashes when using nativeSSLEngine. Fixed in version4.1.118.Final.
Medium Severity
-
CVE-2024-47535 (pom): Denial of Service vulnerability in
io.netty:netty-commonversion4.1.114.Finalon Windows applications due to unsafe reading of environment file. Fixed in version4.1.115. -
CVE-2025-25193 (pom): Denial of Service vulnerability in
io.netty:netty-commonversions up to4.1.118.Finaldue to incomplete fix forCVE-2024-47535. Fixed in commitd1fbda62d3a47835d3fb35db8bd42ecc205a5386.
Fixed Vulnerabilities
High Severity
-
CVE-2024-57699: Security issue in
net.minidev:json-smartversions2.5.0through2.5.1, fixed by upgrading to version2.5.2. -
CVE-2025-24970: Vulnerability in
io.netty:netty-handlerversion4.1.116.Final, fixed by upgrading to a later version.
Edited by Daniel Scholl (MS]