3.2 - Security fixes


Security fixes provided in 3.2.3-funcrel

CAST imageCVESeverityDescriptionAffected CAST release
castimaging/admin-centerCVE-2025-22228HIGHspring-security-core: Spring Security BCryptPasswordEncoder does not enforce maximum password length3.2.0-funcrel
castimaging/analysis-nodeCVE-2020-10683CRITICALUpgrade org.dom4j:dom4j to version 2.0.3, 2.1.33.1.1-funcrel
castimaging/analysis-nodeCVE-2019-20916HIGHUpgrade pip to version 19.23.1.1-funcrel
castimaging/analysis-nodeCVE-2021-3572HIGHUpgrade pip to version 21.13.1.1-funcrel
castimaging/analysis-nodeCVE-2022-40897HIGHUpgrade setuptools to version 65.5.13.1.1-funcrel
castimaging/analysis-nodeCVE-2024-6345HIGHUpgrade etuptools to version 70.0.03.1.1-funcrel
castimaging/auth-serviceCVE-2025-22228HIGHspring-security-core: Spring Security BCryptPasswordEncoder does not enforce maximum password length3.2.0-funcrel
castimaging/consoleCVE-2025-22228HIGHspring-security-core: Spring Security BCryptPasswordEncoder does not enforce maximum password length3.2.2-funcrel
castimaging/consoleCVE-2025-24970HIGHUpgrade io.netty:netty-handler to version 4.1.118.Final3.1.1-funcrel; 3.2.2-funcrel
castimaging/consoleCVE-2016-1000027CRITICALUpgrade org.springframework:spring-web to version 6.0.03.1.1-funcrel
castimaging/consoleCVE-2024-38816HIGHUpgrade org.springframework:spring-webflux to version 6.1.13; Upgrade org.springframework:spring-webmvc to version 6.1.133.1.1-funcrel
castimaging/consoleCVE-2024-38819HIGHUpgrade org.springframework:spring-webflux to version 6.1.14; Upgrade org.springframework:spring-webmvc to version 6.1.143.1.1-funcrel
castimaging/consoleCVE-2022-1471HIGHUpgrade org.yaml:snakeyaml to version 2.03.1.1-funcrel
castimaging/gatewayCVE-2025-22228HIGH3.2.2-funcrel

Security fixes provided in 3.2.2-funcrel

CAST imageCVESeverityDescriptionAffected CAST release
castimaging/admin-centerCVE-2024-47072HIGHcom.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream3.2.0-funcrel
castimaging/admin-centerCVE-2019-17495CRITICALCross-site scripting in Swagger-UI3.2.0-funcrel
castimaging/admin-centerCVE-2024-12797HIGHopenssl: RFC7250 handshakes with unauthenticated servers don’t abort as expected3.2.0-funcrel
castimaging/admin-centerCVE-2024-7254HIGHprotobuf: StackOverflow vulnerability in Protocol Buffers3.2.0-funcrel
castimaging/admin-centerCVE-2024-56337HIGHtomcat: Incomplete fix for3.2.0-funcrel
castimaging/admin-centerCVE-2025-24813CRITICALtomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT3.2.0-funcrel
castimaging/admin-centerCVE-2024-50379HIGHtomcat: RCE due to TOCTOU issue in JSP compilation3.2.0-funcrel
castimaging/admin-centerCVE-2025-24970HIGHUpgrade io.netty:netty-handler to version 4.1.118.Final3.1.1-funcrel
castimaging/admin-centerCVE-2016-1000027CRITICALUpgrade org.springframework:spring-web to version 6.0.03.1.1-funcrel
castimaging/admin-centerCVE-2024-38816HIGHUpgrade org.springframework:spring-webflux to version 6.1.13; Upgrade org.springframework:spring-webmvc to version 6.1.133.1.1-funcrel
castimaging/admin-centerCVE-2024-38819HIGHUpgrade org.springframework:spring-webflux to version 6.1.14; Upgrade org.springframework:spring-webmvc to version 6.1.143.1.1-funcrel
castimaging/admin-centerCVE-2022-1471HIGHUpgrade org.yaml:snakeyaml to version 2.03.1.1-funcrel
castimaging/ai-serviceCVE-2024-39689HIGHUpgrade certifi to version 2024.07.043.1.1-funcrel
castimaging/ai-serviceCVE-2024-1135HIGHUpgrade gunicorn to version 22.0.03.1.1-funcrel
castimaging/ai-serviceCVE-2024-3651HIGHUpgrade idna to version 3.73.1.1-funcrel
castimaging/ai-serviceCVE-2024-6345HIGHUpgrade setuptools to version 70.0.03.1.1-funcrel
castimaging/ai-serviceCVE-2023-6730CRITICALUpgrade transformers to version 4.36.03.1.1-funcrel
castimaging/ai-serviceCVE-2023-7018HIGHUpgrade transformers to version 4.36.03.1.1-funcrel
castimaging/ai-serviceCVE-2024-49768HIGHUpgrade waitress to version 3.0.13.1.1-funcrel
castimaging/ai-serviceCVE-2024-49769HIGHUpgrade waitress to version 3.0.13.1.1-funcrel
castimaging/analysis-nodeCVE-2024-47175HIGHcups: libppd: remote command injection via attacker controlled data in PPD file3.2.0-funcrel
castimaging/analysis-nodeCVE-2025-21172HIGHdotnet: .NET and Visual Studio Remote Code Execution Vulnerability3.2.0-funcrel
castimaging/analysis-nodeCVE-2025-21173HIGHdotnet: .NET Elevation of Privilege Vulnerability3.2.0-funcrel
castimaging/analysis-nodeCVE-2025-21176HIGHdotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability3.2.0-funcrel
castimaging/analysis-nodeCVE-2024-2961HIGHglibc: Out of bounds write in iconv may lead to remote code execution3.2.0-funcrel
castimaging/analysis-nodeCVE-2024-10963HIGHpam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass3.2.0-funcrel
castimaging/analysis-nodeCVE-2024-10041HIGHpam: libpam: Libpam vulnerable to read hashed password3.2.0-funcrel
castimaging/analysis-nodeCVE-2024-12085HIGHrsync: Info Leak via Uninitialized Stack Contents3.2.0-funcrel
castimaging/analysis-nodeCVE-2024-8508HIGHunbound: Unbounded name compression could lead to Denial of Service3.2.0-funcrel
castimaging/analysis-nodeCVE-2024-1488HIGHunbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation3.2.0-funcrel
castimaging/analysis-nodeCVE-2025-21171HIGHdotnet: .NET Remote Code Execution Vulnerability3.2.0-funcrel
castimaging/analysis-nodeCVE-2024-7254HIGHUpgrade com.google.protobuf:protobuf-java to version 3.25.5, 4.27.5, 4.28.23.1.1-funcrel
castimaging/analysis-nodeCVE-2023-24998HIGHUpgrade commons-fileupload:commons-fileupload to version 1.53.1.1-funcrel
castimaging/analysis-nodeCVE-2024-47554HIGHUpgrade commons-io:commons-io to version 2.14.03.1.1-funcrel
castimaging/analysis-nodeCVE-2012-6153HIGHUpgrade org.apache.httpcomponents:httpclient to version 4.2.33.1.1-funcrel
castimaging/analysis-nodeCVE-2022-41404HIGHUpgrade org.ini4j:ini4j to version 0.5.43.1.1-funcrel
castimaging/analysis-nodeCVE-2024-1597HIGHUpgrade org.postgresql:postgresql to version 42.2.28, 42.3.9, 42.4.4, 42.5.5, 42.6.1, 42.7.23.1.1-funcrel
castimaging/analysis-nodeCVE-2024-4340HIGHUpgrade sqlparse to version 0.5.03.1.1-funcrel
castimaging/auth-serviceCVE-2024-47554HIGHapache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader3.2.0-funcrel
castimaging/auth-serviceCVE-2024-47072HIGHcom.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream3.2.0-funcrel
castimaging/auth-serviceCVE-2024-12797HIGHopenssl: RFC7250 handshakes with unauthenticated servers don’t abort as expected3.2.0-funcrel
castimaging/auth-serviceCVE-2024-38819HIGHorg.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks3.2.0-funcrel
castimaging/auth-serviceCVE-2024-38821CRITICALSpring-WebFlux: Authorization Bypass of Static Resources in WebFlux Applications3.2.0-funcrel
castimaging/auth-serviceCVE-2024-38816HIGHspring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource3.2.0-funcrel
castimaging/auth-serviceCVE-2025-24970HIGHUpgrade io.netty:netty-handler to version 4.1.118.Final3.1.1-funcrel
castimaging/auth-serviceCVE-2024-57699HIGHUpgrade net.minidev:json-smart to version 2.5.23.1.1-funcrel
castimaging/consoleCVE-2024-47072HIGHcom.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream3.1.1-funcrel
castimaging/consoleCVE-2024-12797HIGHUpgrade libcrypto3 to version 3.3.3-r0; Upgrade libssl3 to version 3.3.3-r0; Upgrade openssl to version 3.3.3-r03.1.1-funcrel
castimaging/etl-serviceCVE-2021-43565HIGHUpgrade golang.org/x/crypto to version 0.0.0-20211202192323-5770296d904e3.1.1-funcrel
castimaging/etl-serviceCVE-2022-27191HIGHUpgrade golang.org/x/crypto to version 0.0.0-20220314234659-1baeb1ce4c0b3.1.1-funcrel
castimaging/etl-serviceCVE-2024-45337HIGHUpgrade golang.org/x/crypto to version 0.31.03.1.1-funcrel
castimaging/etl-serviceCVE-2022-29526HIGHUpgrade golang.org/x/sys to version 0.0.0-20220412211240-33da011f77ad3.1.1-funcrel
castimaging/etl-serviceCVE-2023-29403CRITICALUpgrade stdlib to version 1.19.10, 1.20.53.1.1-funcrel
castimaging/etl-serviceCVE-2023-29406HIGHUpgrade stdlib to version 1.19.11, 1.20.63.1.1-funcrel
castimaging/etl-serviceCVE-2023-29409HIGHUpgrade stdlib to version 1.19.12, 1.20.7, 1.21.0-rc.43.1.1-funcrel
castimaging/etl-serviceCVE-2023-39325HIGHUpgrade stdlib to version 1.20.10, 1.21.33.1.1-funcrel
castimaging/etl-serviceCVE-2023-45283HIGHUpgrade stdlib to version 1.20.11, 1.21.4, 1.20.12, 1.21.53.1.1-funcrel
castimaging/etl-serviceCVE-2024-24790CRITICALUpgrade stdlib to version 1.21.11, 1.22.43.1.1-funcrel
castimaging/etl-serviceCVE-2024-24791HIGHUpgrade stdlib to version 1.21.12, 1.22.53.1.1-funcrel
castimaging/etl-serviceCVE-2023-45289HIGHUpgrade stdlib to version 1.21.8, 1.22.13.1.1-funcrel
castimaging/etl-serviceCVE-2023-45290HIGHUpgrade stdlib to version 1.21.8, 1.22.13.1.1-funcrel
castimaging/etl-serviceCVE-2024-24783HIGHUpgrade stdlib to version 1.21.8, 1.22.13.1.1-funcrel
castimaging/etl-serviceCVE-2024-24784HIGHUpgrade stdlib to version 1.21.8, 1.22.13.1.1-funcrel
castimaging/etl-serviceCVE-2024-24785HIGHUpgrade stdlib to version 1.21.8, 1.22.13.1.1-funcrel
castimaging/etl-serviceCVE-2023-45288HIGHUpgrade stdlib to version 1.21.9, 1.22.23.1.1-funcrel
castimaging/etl-serviceCVE-2025-22866HIGHUpgrade stdlib to version 1.22.12, 1.23.6, 1.24.0-rc.33.1.1-funcrel
castimaging/etl-serviceCVE-2024-34155HIGHUpgrade stdlib to version 1.22.7, 1.23.13.1.1-funcrel
castimaging/etl-serviceCVE-2024-34156HIGHUpgrade stdlib to version 1.22.7, 1.23.13.1.1-funcrel
castimaging/etl-serviceCVE-2024-34158HIGHUpgrade stdlib to version 1.22.7, 1.23.13.1.1-funcrel
castimaging/gatewayCVE-2024-47072HIGHcom.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream3.2.0-funcrel
castimaging/gatewayCVE-2024-47072HIGHcom.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream3.2.0-funcrel
castimaging/gatewayCVE-2024-38819HIGHorg.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks3.2.0-funcrel
castimaging/gatewayCVE-2024-38819HIGHorg.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks3.2.0-funcrel
castimaging/gatewayCVE-2024-7254HIGHprotobuf: StackOverflow vulnerability in Protocol Buffers3.2.0-funcrel
castimaging/gatewayCVE-2024-38816HIGHspring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource3.2.0-funcrel
castimaging/gatewayCVE-2024-38816HIGHspring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource3.2.0-funcrel
castimaging/gatewayCVE-2024-56337HIGHtomcat: Incomplete fix for3.2.0-funcrel
castimaging/gatewayCVE-2024-50379HIGHtomcat: RCE due to TOCTOU issue in JSP compilation3.2.0-funcrel
castimaging/gatewayCVE-2025-24813HIGHtomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT3.2.0-funcrel
castimaging/gatewayCVE-2025-24970HIGHUpgrade io.netty:netty-handler to version 4.1.118.Final3.1.1-funcrel
castimaging/gatewayCVE-2025-24970HIGHUpgrade io.netty:netty-handler to version 4.1.118.Final3.1.1-funcrel
castimaging/gatewayCVE-2024-12797HIGHUpgrade libcrypto3 to version 3.3.3-r0; Upgrade libssl3 to version 3.3.3-r0; Upgrade openssl to version 3.3.3-r03.1.1-funcrel
castimaging/gatewayCVE-2024-12797HIGHUpgrade libcrypto3 to version 3.3.3-r0; Upgrade libssl3 to version 3.3.3-r0; Upgrade openssl to version 3.3.3-r03.1.1-funcrel
castimaging/sso-serviceCVE-2024-7341HIGHwildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters3.2.0-funcrel
castimaging/sso-serviceCVE-2024-8698HIGHkeycloak-saml-core: Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak3.2.0-funcrel
castimaging/viewerCVE-2024-45337HIGHUpgrade golang.org/x/crypto to version 0.31.03.1.1-funcrel
castimaging/viewerCVE-2024-45337HIGHUpgrade golang.org/x/crypto to version 0.31.03.1.1-funcrel
castimaging/viewerCVE-2024-45338HIGHUpgrade golang.org/x/net to version 0.33.03.1.1-funcrel
castimaging/viewerCVE-2024-24791HIGHUpgrade stdlib to version 1.21.12, 1.22.53.1.1-funcrel
castimaging/viewerCVE-2025-22866HIGHUpgrade stdlib to version 1.22.12, 1.23.6, 1.24.0-rc.33.1.1-funcrel
castimaging/viewerCVE-2024-34155HIGHUpgrade stdlib to version 1.22.7, 1.23.13.1.1-funcrel
castimaging/viewerCVE-2024-34156HIGHUpgrade stdlib to version 1.22.7, 1.23.13.1.1-funcrel
castimaging/viewerCVE-2024-34158HIGHUpgrade stdlib to version 1.22.7, 1.23.13.1.1-funcrel