Full List of Enhancements:
Bug Fixes:
Deprecated Library Updates:
Updated or removed the following deprecated libraries:
Remove Deprecated MomentJS Library
Upgraded the EOL Joda-time v2.9 dependency in Eureka
Upgrade the ORACLE JavaBeans Activation Framework 1.1 in MLC Service
Security Fixes/Patches:
NOTE: many of the below are NOT related to ModelOp software, but rather related to dependencies
Addressed CVE-2023-34036 - Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers.
Addressed CVE-2023-4759 - a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree
Addressed CVE-2016-1000027 - Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE)
Addressed CVE-2023-6378 CVE-2023-6481 - Logback: Serialization vulnerability in logback receiver
Addressed CVE-2024-21634 - Allocation of Resources Without Limits or Throttling
Addressed CVE-2024-38816 - spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource
Addressed CVE-2024-47554 commons-io on Document Service
Addressed CVE-2022-40152 - DOS risk with Woodstock-core dependency