Move os-core-common-spring6 to os-core-common (latest)
Changes
- Updated
os-core-common
version from0.26.0-rc2
to3.3.0
- Updated
json-smart
version from2.5.1
to2.5.2
- Updated
core-lib-azure
version from2.0.3
to2.0.4
- Updated
os-core-lib-ibm
version from0.26.0-rc8
to0.27.0-rc3
- Changed dependency
os-core-common-spring6
toos-core-common
- Updated test case
AuthorizationServiceForServiceAdminImplTest
to useJWTClaimsSet
andJWSObject
instead ofJws<Claims>
Security Impact
New Vulnerabilities
High Severity
-
CVE-2025-24970 (pom): Vulnerability in
io.netty:netty-handler
version4.1.114.Final
whereSslHandler
doesn't correctly validate packets, leading to potential native crashes when using nativeSSLEngine
. Fixed in version4.1.118.Final
.
Medium Severity
-
CVE-2024-47535 (pom): Denial of Service vulnerability in
io.netty:netty-common
version4.1.114.Final
on Windows applications due to unsafe reading of environment file. Fixed in version4.1.115
. -
CVE-2025-25193 (pom): Denial of Service vulnerability in
io.netty:netty-common
versions up to4.1.118.Final
due to incomplete fix forCVE-2024-47535
. Fixed in commitd1fbda62d3a47835d3fb35db8bd42ecc205a5386
.
Fixed Vulnerabilities
High Severity
-
CVE-2024-57699: Security issue in
net.minidev:json-smart
versions2.5.0
through2.5.1
, fixed by upgrading to version2.5.2
. -
CVE-2025-24970: Vulnerability in
io.netty:netty-handler
version4.1.116.Final
, fixed by upgrading to a later version.
Edited by Daniel Scholl (MS]