3.4 - Security fixes


Security fixes provided in 3.4.5-funcrel

CAST serviceCVESeverityDescription/PackageAffected CAST release
admin-centerCVE-2025-4949Criticalorg.eclipse.jgit:org.eclipse.jgit3.4.4-funcrel
admin-centerCVE-2020-36843Highnet.i2p.crypto:eddsa3.4.4-funcrel
admin-centerCVE-2025-46392Highcommons-configuration:commons-configuration3.4.4-funcrel
admin-centerCVE-2025-48924Highorg.apache.commons:commons-lang3, commons-lang:commons-lang3.4.4-funcrel
ai-serviceCVE-2025-7709Criticallibsqlite3-03.4.4-funcrel
ai-serviceCVE-2025-9230Criticalopenssl, libssl3t64, openssl-provider-legacy3.4.4-funcrel
ai-serviceCVE-2025-3262Hightransformers3.4.4-funcrel
ai-serviceCVE-2025-6921Hightransformers3.4.4-funcrel
ai-serviceCVE-2025-8941Highlibpam0g, libpam-runtime, libpam-modules, libpam-modules-bin3.4.4-funcrel
ai-serviceCVE-2025-9231Highopenssl, libssl3t64, openssl-provider-legacy3.4.4-funcrel
ai-serviceCVE-2025-9232Highopenssl, libssl3t64, openssl-provider-legacy3.4.4-funcrel
ai-serviceCVE-2025-3263Mediumtransformers3.4.4-funcrel
ai-serviceCVE-2025-3264Mediumtransformers3.4.4-funcrel
ai-serviceCVE-2025-3777Mediumtransformers3.4.4-funcrel
ai-serviceCVE-2025-3933Mediumtransformers3.4.4-funcrel
ai-serviceCVE-2025-5197Mediumtransformers3.4.4-funcrel
ai-serviceCVE-2025-6051Mediumtransformers3.4.4-funcrel
ai-serviceCVE-2025-6638Mediumtransformers3.4.4-funcrel
ai-serviceCVE-2025-8869Mediumpip3.4.4-funcrel
analysis-nodeCVE-2025-48924Highorg.apache.commons:commons-lang33.4.4-funcrel
analysis-nodeCVE-2022-45787Mediumorg.apache.james:apache-mime4j3.4.4-funcrel
analysis-nodeCVE-2023-4218Mediumorg.eclipse.platform:org.eclipse.core.runtime3.4.4-funcrel
analysis-nodeCVE-2025-8869Mediumpip3.4.4-funcrel
authCVE-2025-46392Highcommons-configuration:commons-configuration3.4.4-funcrel
authCVE-2025-48924Highorg.apache.commons:commons-lang3, commons-lang:commons-lang3.4.4-funcrel
gatewayCVE-2025-22227Highio.projectreactor.netty:reactor-netty-http3.4.4-funcrel
gatewayCVE-2025-41249Highorg.springframework:spring-core3.4.4-funcrel
gatewayCVE-2025-46392Highcommons-configuration:commons-configuration3.4.4-funcrel
gatewayCVE-2025-48924Highorg.apache.commons:commons-lang3, commons-lang:commons-lang3.4.4-funcrel
gatewayCVE-2020-13956Highorg.apache.httpcomponents:httpclient3.4.4-funcrel
gatewayCVE-2025-41242Highorg.springframework:spring-webmvc3.4.4-funcrel
neo4jCVE-2025-22227Highio.projectreactor.netty:reactor-netty-http3.4.4-funcrel
neo4jCVE-2025-48924Highorg.apache.commons:commons-lang33.4.4-funcrel
neo4jCVE-2025-53864Highcom.nimbusds:nimbus-jose-jwt3.4.4-funcrel
sso-serviceCVE-2025-48924Highorg.apache.commons:commons-lang33.4.4-funcrel
imaging-viewerCVE-2025-9230Criticallibssl3, libcrypto33.4.4-funcrel
imaging-viewerCVE-2025-9231Highlibssl3, libcrypto33.4.4-funcrel
imaging-viewerCVE-2025-9232Highlibssl3, libcrypto33.4.4-funcrel
imaging-viewerCVE-2025-47910MediumGo3.4.4-funcrel
postgresqlCVE-2025-49794Criticallibxml23.4.4-funcrel
postgresqlCVE-2025-49796Criticallibxml23.4.4-funcrel
postgresqlCVE-2025-49795Highlibxml23.4.4-funcrel
postgresqlCVE-2025-6021Highlibxml23.4.4-funcrel
postgresqlCVE-2025-6170Lowlibxml23.4.4-funcrel

Security fixes provided in 3.4.4-funcrel

CAST imageCVESeverityDescriptionAffected CAST release
admin-centerCVE-2025-41249HIGHorg.springframework/spring-core: Spring Framework Annotation Detection Vulnerability3.4.3-funcrel
auth-serviceCVE-2025-41248HIGHorg.springframework.security/spring-security-core: Spring Security authorization bypass3.4.3-funcrel
auth-serviceCVE-2025-41249HIGHorg.springframework/spring-core: Spring Framework Annotation Detection Vulnerability3.4.3-funcrel
gatewayCVE-2025-41249HIGHorg.springframework/spring-core: Spring Framework Annotation Detection Vulnerability3.4.3-funcrel
analysis-nodeCVE-2025-58060HIGHcups: Authentication Bypass in CUPS Authorization Handling3.4.3-funcrel
dashboardsCVE-2025-41249HIGHorg.springframework/spring-core: Spring Framework Annotation Detection Vulnerability3.4.3-funcrel
ai-serviceCVE-2025-58050HIGHpcre2: PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS3.4.3-funcrel

Security fixes provided in 3.4.3-funcrel

CAST imageCVESeverityDescriptionAffected CAST release
admin-centerCVE-2025-48989HIGHtomcat: http/2 “MadeYouReset” DoS attack through HTTP/2 control frames3.4.2-funcrel
admin-centerCVE-2025-55163HIGHnetty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability3.4.2-funcrel
analysis-nodeCVE-2025-47273HIGHsetuptools: Path Traversal Vulnerability in setuptools PackageIndex3.4.2_core8.4.5
analysis-nodeCVE-2025-5914HIGHlibarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c3.4.2_core8.4.5
analysis-nodeCVE-2025-6020HIGHlinux-pam: Linux-pam directory Traversal3.4.2_core8.4.5
analysis-nodeCVE-2025-8941HIGHlinux-pam: Incomplete fix for CVE-2025-60203.4.2_core8.4.5
ai-serviceCVE-2025-6984HIGHlangchain-community: Langchain-community insecure XML parsing3.4.2-funcrel
auth-serviceCVE-2025-55163HIGHnetty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability3.4.2-funcrel
consoleCVE-2025-55163HIGHnetty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability3.4.2-funcrel
dashboards-v3CVE-2025-48989HIGHtomcat: http/2 “MadeYouReset” DoS attack through HTTP/2 control frames3.4.2-funcrel
gatewayCVE-2025-48989HIGHtomcat: http/2 “MadeYouReset” DoS attack through HTTP/2 control frames3.4.2-funcrel
gatewayCVE-2025-55163HIGHnetty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability3.4.2-funcrel
neo4jCVE-2025-58060HIGHcups: Authentication Bypass in CUPS Authorization Handling3.4.2-funcrel
neo4jCVE-2025-6020HIGHlinux-pam: Linux-pam directory Traversal3.4.2-funcrel
neo4jCVE-2025-8941HIGHlinux-pam: Incomplete fix for CVE-2025-60203.4.2-funcrel
sso-serviceCVE-2025-55163HIGHnetty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability3.4.2-funcrel
viewer--Removal of fast-glob NPM glob pattern matching package3.4.2-funcrel

Security fixes provided in 3.4.1-funcrel

CAST imageCVESeverityDescriptionAffected CAST release
admin-centerCVE-2022-41404HIGHorg.ini4j: unspecified DoS3.4.0-funcrel
admin-centerCVE-2025-6965CRITICALsqlite: Integer Truncation in SQLite3.4.0-funcrel
analysis-nodeCVE-2022-41404HIGHorg.ini4j: unspecified DoS3.4.0-funcrel_core8.4.4
analysis-nodeCVE-2025-30761HIGHopenjdk: Improve scripting supports (Oracle CPU 2025-07)3.4.0-funcrel_core8.4.4
analysis-nodeCVE-2025-48976HIGHapache-commons-fileupload: Apache Commons FileUpload DoS via part headers3.4.0-funcrel_core8.4.4
auth-serviceCVE-2025-6965CRITICALsqlite: Integer Truncation in SQLite3.4.0-funcrel
consoleCVE-2025-6965CRITICALsqlite: Integer Truncation in SQLite3.4.0-funcrel
dashboardsCVE-2022-41404HIGHorg.ini4j: unspecified DoS3.4.0-funcrel
etl-serviceCVE-2025-22868HIGHgolang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws3.4.0-funcrel
etl-serviceCVE-2025-6965CRITICALsqlite: Integer Truncation in SQLite3.4.0-funcrel
gatewayCVE-2025-6965CRITICALsqlite: Integer Truncation in SQLite3.4.0-funcrel
sso-serviceCVE-2025-30749HIGHopenjdk: Better Glyph drawing (Oracle CPU 2025-07)3.4.0-funcrel
sso-serviceCVE-2025-49146HIGHpgjdbc: pgjdbc insecure authentication in channel binding3.4.0-funcrel
sso-serviceCVE-2025-50059HIGHopenjdk: Improve HTTP client header handling (Oracle CPU 2025-07)3.4.0-funcrel
sso-serviceCVE-2025-50106HIGHopenjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07)3.4.0-funcrel
viewerCVE-2025-22868HIGHgolang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws3.4.0-funcrel
viewerCVE-2025-30749HIGHopenjdk: Better Glyph drawing (Oracle CPU 2025-07)3.4.0-funcrel
viewerCVE-2025-50059HIGHopenjdk: Improve HTTP client header handling (Oracle CPU 2025-07)3.4.0-funcrel
viewerCVE-2025-50106HIGHopenjdk: Glyph out-of-memory access and crash (Oracle CPU 2025-07)3.4.0-funcrel

Security fixes provided in 3.4.0-funcrel

CAST imageCVEDescriptionAffected CAST release
admin-centerCVE-2025-48988tomcat: Apache Tomcat DoS in multipart upload3.3.0-funcrel
admin-centerCVE-2025-49146pgjdbc: pgjdbc insecure authentication in channel binding3.3.0-funcrel
auth-serviceCVE-2025-41235Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies3.3.0-funcrel
ai-serviceCVE-2024-12718cpython: python: Bypass extraction filter to modify file metadata outside extraction directory3.3.0-funcrel
ai-serviceCVE-2025-29087sqlite: Integer Overflow in SQLite concat_ws Function3.3.0-funcrel
ai-serviceCVE-2025-4138cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory3.3.0-funcrel
ai-serviceCVE-2025-4330cpython: python: Extraction filter bypass for linking outside extraction directory3.3.0-funcrel
ai-serviceCVE-2025-4517python: cpython: Arbitrary writes via tarfile realpath overflow3.3.0-funcrel
ai-serviceCVE-2025-4565python-protobuf: Unbounded recursion in Python Protobuf3.3.0-funcrel
ai-serviceCVE-2025-47273setuptools: Path Traversal Vulnerability in setuptools PackageIndex3.3.0-funcrel
analysis-nodeCVE-2025-48379python-pillow: pillow: Pillow DDS Heap Buffer Overflow3.3.0-funcrel_core8.4.3
consoleCVE-2025-41235Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies3.3.0-funcrel
dashboardsCVE-2025-22235org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed3.3.0-funcrel
dashboardsCVE-2025-48988tomcat: Apache Tomcat DoS in multipart upload3.3.0-funcrel
dashboardsCVE-2025-49146pgjdbc: pgjdbc insecure authentication in channel binding3.3.0-funcrel
etl-serviceCVE-2025-22874crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x5093.3.0-funcrel
gatewayCVE-2025-41235Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies3.3.0-funcrel
gatewayCVE-2025-48988tomcat: Apache Tomcat DoS in multipart upload3.3.0-funcrel
neo4jCVE-2025-1948jetty-http2-common: Jetty HTTP/2 Header List Size Vulnerability3.3.0-funcrel
sso-serviceCVE-2025-3501org.keycloak.protocol.services: Keycloak hostname verification3.3.0-funcrel
viewerCVE-2024-12718cpython: python: Bypass extraction filter to modify file metadata outside extraction directory3.3.0-funcrel
viewerCVE-2025-22874crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x5093.3.0-funcrel
viewerCVE-2025-4138cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory3.3.0-funcrel
viewerCVE-2025-4330cpython: python: Extraction filter bypass for linking outside extraction directory3.3.0-funcrel
viewerCVE-2025-4517python: cpython: Arbitrary writes via tarfile realpath overflow3.3.0-funcrel