3.3 - Security fixes


Security fixes provided in 3.3.1-funcrel

CAST imageIssue IDComponentAffected CAST release
analysis-nodeSQ34201DMT - SVN ExtractorImaging Core 8.4.3
analysis-nodeSQ34304Consistency CheckerImaging Core 8.4.3
analysis-nodeSQ34304Analysis RunnerImaging Core 8.4.3
analysis-nodeSQ31101Consistency CheckerImaging Core 8.4.3
analysis-nodeSQ31101Combined ImporterImaging Core 8.4.3
analysis-nodeSQ31103Consistency CheckerImaging Core 8.4.3
analysis-nodeSQ31103Tools RestoreImaging Core 8.4.3
analysis-nodeSQ31103Analysis RunnerImaging Core 8.4.3
analysis-nodeSQ31103CSSAdminImaging Core 8.4.3

Security fixes provided in 3.3.0-funcrel

CAST imageCVESeverityDescriptionAffected CAST release
admin-centerCVE-2024-8176HIGHlibexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat3.2.3
admin-centerCVE-2025-22235HIGHorg.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed3.2.3
admin-centerCVE-2025-27820HIGHorg.apache.httpcomponents.client5/httpclient5: Apache HttpComponents: PSL (Public Suffix List) validation bypass3.2.3
admin-centerCVE-2025-29087HIGHsqlite: Integer Overflow in SQLite concat_ws Function3.2.3
admin-centerCVE-2025-31498HIGHc-ares: c-ares has a use-after-free in read_answers()3.2.3
auth-serviceCVE-2024-10039HIGHkeycloak-core: mTLS passthrough3.2.3
auth-serviceCVE-2024-8176HIGHlibexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat3.2.3
auth-serviceCVE-2025-22235HIGHorg.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed3.2.3
auth-serviceCVE-2025-27820HIGHorg.apache.httpcomponents.client5/httpclient5: Apache HttpComponents: PSL (Public Suffix List) validation bypass3.2.3
auth-serviceCVE-2025-29087HIGHsqlite: Integer Overflow in SQLite concat_ws Function3.2.3
auth-serviceCVE-2025-31498HIGHc-ares: c-ares has a use-after-free in read_answers()3.2.3
consoleCVE-2024-8176HIGHlibexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat3.2.3
consoleCVE-2025-22235HIGHorg.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed3.2.3
consoleCVE-2025-29087HIGHsqlite: Integer Overflow in SQLite concat_ws Function3.2.3
consoleCVE-2025-31498HIGHc-ares: c-ares has a use-after-free in read_answers()3.2.3
gatewayCVE-2024-8176HIGHlibexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat3.2.3
gatewayCVE-2025-22235HIGHorg.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed3.2.3
gatewayCVE-2025-27820HIGHorg.apache.httpcomponents.client5/httpclient5: Apache HttpComponents: PSL (Public Suffix List) validation bypass3.2.3
gatewayCVE-2025-29087HIGHsqlite: Integer Overflow in SQLite concat_ws Function3.2.3
gatewayCVE-2025-31498HIGHc-ares: c-ares has a use-after-free in read_answers()3.2.3
sso-serviceCVE-2024-10039HIGHkeycloak-core: mTLS passthrough3.2.3
sso-serviceCVE-2024-10270HIGHorg.keycloak:keycloak-services: Keycloak Denial of Service3.2.3
sso-serviceCVE-2024-10451HIGHorg.keycloak:keycloak-quarkus-server: Sensitive Data Exposure in Keycloak Build Process3.2.3
sso-serviceCVE-2024-12397HIGHio.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling3.2.3
sso-serviceCVE-2025-24970HIGHio.netty:netty-handler: SslHandler doesn’t correctly validate packets which can lead to native crash when using native SSLEngine3.2.3
ai-serviceCVE-2025-31115HIGHxz: XZ has a heap-use-after-free bug in threaded .xz decoder3.2.3
ai-serviceCVE-2025-43859CRITICALh11: h11 accepts some malformed Chunked-Encoding bodies3.2.3
viewerCVE-2025-21587HIGHopenjdk: Better TLS connection support (Oracle CPU 2025-04)3.2.3
viewerCVE-2025-23083HIGHnodejs: Node.js Worker Thread Exposure via Diagnostics Channel3.2.3
viewerCVE-2025-29087HIGHsqlite: Integer Overflow in SQLite concat_ws Function3.2.3
viewerCVE-2025-31115HIGHxz: XZ has a heap-use-after-free bug in threaded .xz decoder3.2.3