graph-studio
Graph Lakehouse Patched Vulnerabilities
This page provides information about the common security vulnerabilities that were patched in Graph Lakehouse.
| Graph Lakehouse Releases |
|---|
- Graph Lakehouse 2026.1 DB 3.4.0
- Graph Lakehouse 2026.0 DB 3.3.1
- Graph Lakehouse 2026.0 DB 3.3.0
- Graph Lakehouse 2025.0 DB 3.2.2
- Graph Lakehouse 2025.0 DB 3.2.1
- Graph Lakehouse 2025.0 DB 3.2.0
- Graph Lakehouse 3.1.9
- Graph Lakehouse 3.1.8
- Graph Lakehouse 3.1.7
- Graph Lakehouse 3.1.6
- Graph Lakehouse 3.1.5
- Graph Lakehouse 3.1.4
- Graph Lakehouse 3.1.3
- Graph Lakehouse 3.1.2
- Graph Lakehouse 3.1.1
- Graph Lakehouse 3.1.0
- Graph Lakehouse 3.0.0
- AnzoGraph 2.5.23
- AnzoGraph 2.5.22
- AnzoGraph 2.5.21
- AnzoGraph 2.5.20
- AnzoGraph 2.5.19
- AnzoGraph 2.5.17
- AnzoGraph 2.5.15
- AnzoGraph 2.5.14
- AnzoGraph 2.5.13
- AnzoGraph 2.5.12
- AnzoGraph 2.5.11
- AnzoGraph 2.5.10
- AnzoGraph 2.5.8
- AnzoGraph 2.5.7
- AnzoGraph 2.5.6
- AnzoGraph 2.5.5
- AnzoGraph 2.5.4
- AnzoGraph 2.5.3
- AnzoGraph 2.5.2
- AnzoGraph 2.5.1
|
Graph Lakehouse 2026.1 DB 3.4.0
- CVE-2025-48734: The Apache Commons BeanUtils dependency was updated to remediate a potential Improper Access Control vulnerability.
- CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
- CVE-2025-12383: Eclipse Jersey was updated to remediate a potential security vulnerability.
- CVE-2025-9086:
curlhas been updated to correct a bug in its path comparison logic that can cause an out-of-bounds read or allow an insecure HTTP response to override a secure cookie set over HTTPS when the same cookie name and a path of “/” are used. - CVE-2025-59250: The JDBC driver for SQL server was updated to prevent unauthorized attackers from spoofing over a network.
- CVE-2025-27821: The Apache Hadoop package was updated to mediate a potential out-of-bounds write vulnerability.
- CVE-2026-1605: Eclipse Jersey was updated to remediate this potential security vulnerability.
- CVE-2026-29000: The pac4j-jwt package was updated to address an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens.
- GHSA-72hv-8253-57qq: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
- CVE-2026-3805:
curlhas been updated to address an issue in which it accesses memory that has already been freed when handling a second server message block (SMB) request to the same host. - CVE-2025-53864: Upgraded com.nimbusds:nimbus-jose-jwt to address medium-severity vulnerabilities.
- CVE-2026-33870, CVE-2026-33871: The Netty library dependency was updated to version 4.1.132.Final to remediate a potential Denial of Service (DoS) vulnerability.
- CVE-2026-33186: The golang /grpc package was updated to remediate this potential critical security vulnerability.
Graph Lakehouse 2026.0 DB 3.3.1
- CVE-2025-68121, CVE-2025-61726, CVE-2025-681728, and CVE-2025-61730: The Go standard library was updated to mitigate critical security vulnerabilities including DoS attacks, memory exhaustion, and unauthorized session resumption.
- CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
- CVE-2025-9086:
curlhas been updated to correct a bug in its path comparison logic that can cause an out-of-bounds read or allow an insecure HTTP response to override a secure cookie set over HTTPS when the same cookie name and a path of “/” are used. - CVE-2025-12383: Eclipse Jersey was updated to remediate a potential security vulnerability.
- CVE-2025-58057: netty-codec was updated to remediate a potential DoS vulnerability via zip bomb-style attack.
- CVE-2025-58056: netty-codec was updated to remediate a request smuggling dependency owing to the incorrect parsing of chunk extensions.
- CVE-2025-59250: The JDBC driver for SQL server was updated to prevent unauthorized attackers from spoofing over a network.
- CVE-2025-27821: The Apache Hadoop package was updated to mediate a potential out-of-bounds write vulnerability.
Graph Lakehouse 2026.0 DB 3.3.0
- CVE-2025-46762: The org.apache.parquet dependency was updated to remediate this vulnerability.
- CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
- CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
- CVE-2025-52999: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
- CVE-2025-32989, CVE-2025-32990, CVE-2025-32988, CVE-2025-6395: The GnuTLS library was updated to remediate various potential vulnerabilities related to this dependency.
Graph Lakehouse 2025.0 DB 3.2.2
- CVE-2025-22870 : The golang net/http, x/net/proxy, and x/net/http/httpproxy package dependencies were updated to remediate this proxy bypass vulnerability.
- CVE-2025-27553 : The Apache Commons VFS dependency for GDI was updated to version 2.10.0 to remediate this Relative Path Traversal vulnerability.
- CVE-2025-22871 : The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
- CVE-2025-22872 : The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
- CVE-2025-1948 : The Eclipse Jetty dependency was updated to remediate this vulnerability in the Jetty HTTP/2 server.
Graph Lakehouse 2025.0 DB 3.2.1
- CVE-2024-56171 and CVE-2025-24928: The libxml2 library dependency was upgraded to version 2.13.6 to remediate this "use-after-free" (UAF) vulnerability.
- CVE-2025-0665 and CVE-2025-0725: The libcurl library dependency was upgraded to version 8.12.0 to remediate this vulnerability.
- CVE-2025-24970: The Netty/Handler (io.netty:netty-handler) library dependency for GDI and the frontend user interface was updated to version 4.1.118.Final to remediate this vulnerability.
- CVE-2020-8908, CVE-2024-47535, CVE-2023-34462:The Databricks JDBC driver dependency was updated to version 2.7.1 to remediate these vulnerabilities in its third-party libraries. See https://docs.databricks.com/aws/en/release-notes/product/2025/january#databricks-jdbc-driver-271 for more details.
Graph Lakehouse 2025.0 DB 3.2.0
- GHSA-wjxj-5m7g-mg7q and CVE-2023-33202 : The Bouncy Castle for Java dependency was updated to remediate a potential Denial of Service (DoS) vulnerability within the Bouncy Castle org.bouncycastle.openssl.PEMParser class.
- CVE-2023-31147, CVE-2023-31130, CVE-2022-4904, and CVE-2023-31124: The c-ares library dependency was updated to remediate these vulnerabilities.
- GHSA-xqfj-vm6h-2x34, CVE-2021-35517, GHSA-mc84-pj99-q6hh, CVE-2021-36090, GHSA-crv7-7245-f45f, CVE-2021-35516, GHSA-7hfm-57qf-j43q, CVE-2021-35515, GHSA-4g9r-vxhx-9pgx, and CVE-2024-25710: The Apache Commons Compress package dependency was updated to remediate these potential Denial of Service (DoS) attack vulnerabilities.
- GHSA-8r3f-844c-mc37, CVE-2024-24786, GHSA-8r3f-844c-mc37, and CVE-2024-24786: The google.golang.org/protobuf module dependency was updated to remediate these vulnerabilities in the Golang protojson.Unmarshal function.
- GHSA-7g45-4rm6-3mm3, CVE-2023-2976, GHSA-5mg8-w23w-74h3, and CVE-2020-8908: The Google Guava dependency was updated to remediate these vulnerabilities.
- GHSA-58qw-p7qm-5rvh : The Eclipse Jetty dependency was updated to remediate this XML external entity (XXE) vulnerability in XmlParser.
- GHSA-vmq6-5m68-f53m and CVE-2023-6378 : The logback framework dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
- GHSA-668q-qrv7-99fm and CVE-2021-42550 : The logback framework dependency was updated to remediate a potential arbitrary code execution (ACE) vulnerability.
- GHSA-gvpg-vgmx-xg6w and CVE-2023-52428 : The Connect2id Nimbus JOSE+JWT dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
- CVE-2024-45338 : The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
- CVE-2024-47535 : The Netty framework dependency for the frontend user interface was updated to remediate a potential Denial of Service (DoS) vulnerability.
- CVE-2024-47875 : The DOMPurify dependency was upgraded to remediate this nesting-based Mutated Cross-site scripting (mXSS) vulnerability.
- CVE-2021-41033 : The Eclipse Equinox dependency was upgraded to remediate this man-in-the-middle attack vulnerability.
Graph Lakehouse 3.1.9
- GHSA-72hv-8253-57qq: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
- CVE-2026-29000: The pac4j-jwt package was updated to address an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens.
- CVE-2026-25646: The libpng library was updated to remediate this potential out-of-bounds read vulnerability.
- CVE-2026-1605: Eclipse Jersey was updated to remediate this potential security vulnerability.
- CVE-2025-58057: netty-codec was updated to remediate a potential DoS vulnerability via zip bomb-style attack.
- CVE-2025-58056: netty-codec was updated to remediate a request smuggling dependency owing to the incorrect parsing of chunk extensions.
- CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
- CVE-2025-54988: The Apache Tika package was updated to remediate this potential security vulnerability.
- CVE-2025-12383: Eclipse Jersey was updated to remediate a potential security vulnerability.
- CVE-2025-9086:
curlhas been updated to correct a bug in its path comparison logic that can cause an out-of-bounds read or allow an insecure HTTP response to override a secure cookie set over HTTPS when the same cookie name and a path of “/” are used.
Graph Lakehouse 3.1.8
- CVE-2024-45336: The golang net/http package dependency was updated to remediate this vulnerability.
- CVE-2024-45341: The golang crypto/x509 package dependency was updated to remediate this vulnerability.
- CVE-2025-22870: The golang net/http, x/net/proxy, and x/net/http/httpproxy package dependencies were updated to remediate this proxy bypass vulnerability.
- CVE-2025-22871: The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
- CVE-2025-22872: The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
- CVE-2025-27553: The Apache Commons VFS dependency for GDI was updated to version 2.10.0 to remediate this Relative Path Traversal vulnerability.
- CVE-2025-48734: The Apache commons dependency was updated to remediate this potential Improper Access Control vulnerability.
- CVE-2025-52999: The jackson-core dependency was updated to remediate this potential Denial of Service (DoS) vulnerability.
- CVE-2025-47907: The golang database/sql package dependency was updated to remediate vulnerability.
- CVE-2025-4674: The golang package was updated to remediate issues related to unexpected code execution.
- CVE-2025-55163: The Netty library dependency for the front-end user interface was updated to remediate a potential HTTP/2 MadeYouReset Distributed DoS vulnerability.
- CVE-2025-5115: The Eclipse Jetty dependency for the frontend user interface was updated to remediate a potential HTTP/2 MadeYouReset DoS vulnerability.
Graph Lakehouse 3.1.7
- CVE-2025-0665 and CVE-2025-0725: The libcurl library dependency was updated to version 8.12.0 to remediate this vulnerability.
- CVE-2025-24970: The Netty/Handler (io.netty:netty-handler) library dependency for GDI and the frontend user interface was updated to version 4.1.118.Final to remediate this vulnerability.
- CVE-2020-8908, CVE-2024-47535, CVE-2023-34462:The Databricks JDBC driver dependency was updated to version 2.7.1 to remediate these vulnerabilities in its third-party libraries. See https://docs.databricks.com/aws/en/release-notes/product/2025/january#databricks-jdbc-driver-271 for more details.
Graph Lakehouse 3.1.6
- GHSA-58qw-p7qm-5rvh: The Eclipse Jetty dependency was updated to remediate this XML external entity (XXE) vulnerability in the jetty XmlParser.
- CVE-2024-43382: The Snowflake JDBC driver dependency was updated to remediate this incorrect security setting vulnerability.
- GHSA-w32m-9786-jp63, CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
Graph Lakehouse 3.1.5
- CVE-2024-47554: The Apache Commons IO dependency of the Neptune extension library of Graph Lakehouse DB was upgraded to version 2.15.1 to remediate this Uncontrolled Resource Consumption vulnerability.
- CVE-2024-48910: The DOMPurify dependency was upgraded to version 2.4.2 to remediate this Prototype Pollution vulnerability.
Graph Lakehouse 3.1.4
- CVE-2024-34156: The encoding/gob package dependency was updated to remediate this stack exhaustion vulnerability (Go upgraded to version 1.23.1).
- CVE-2024-7254: The Protocol Buffers parser dependency was updated to remediate this improper input validation vulnerability.
- CVE-2024-45801: The DOMPurify dependency was upgraded to remediate this XSS attack vulnerability.
- CVE-2024-43591: The Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability was remediated.
- CVE-2024-2398: The libcurl dependency was upgraded from version 8.1.2 to 8.10.1 to further remediate this HTTP/2 push headers memory-leak vulnerability.
- CVE-2024-47554: The Apache Commons IO dependency was upgraded to version 2.15.1 to remediate this Uncontrolled Resource Consumption vulnerability.
- CVE-2024-8184: The Eclipse jetty dependency was updated to version 12.0.12 to remediate a potential remote Denial of Service (DoS) attack vulnerability.
Graph Lakehouse 3.1.3
- CVE-2024-2398: The libcurl dependency was updated to remediate this HTTP/2 push headers memory-leak vulnerability.
- CVE-2024-6345: The pypa/setuptools dependency was upgraded to remediate this vulnerability.
Graph Lakehouse 3.1.2
- CVE-2024-24790: The golang net/netip package dependency was updated to remediate this vulnerability (Go upgraded to version 1.22.4).
- CVE-2023-45288: The golang net/http and x/net/http2 package dependencies were updated to remediate this HTTP/2 CONTINUATION Flood vulnerability.
- CVE-2023-6597: The CPython dependency for the frontend user interface was updated to remediate this tempfile.TemporaryDirectory class vulnerability.
- CVE-2023-52424: A dependency for the frontend user interface was updated to remediate the SSID Confusion Attack vulnerability.
- CVE-2024-24788: A golang dependency was updated to remediate this vulnerability (Go upgraded to version 1.22.4).
Graph Lakehouse 3.1.1
- CVE-2024-30172: The BC Java Cryptography API dependencies for the frontend user interface were updated to remediate this vulnerability.
- CVE-2024-21634: The BC Java, BC-FJA, and BC C# .Net library dependencies for the frontend user interface were updated to remediate this vulnerability.
- CVE-2024-29857: The ion-java dependency library was updated to remediate a possible Denial of Service (DoS) vulnerability.
Graph Lakehouse 3.1.0
CVE-2023-32067: The c-ares dependency library was updated to remediate a possible Denial of Service (DoS) vulnerability.
CVE-2023-30535: The Snowflake JDBC driver was updated to version 3.13.29 to remediate a possible command injection vulnerability.
CVE-2023-1370: The json-smart dependency for the frontend user interface was updated to remediate a possible stack overflow vulnerability.
CVE-2022-46175: The JSON5 dependency for the frontend user interface was updated to remediate this vulnerability.
CVE-2022-31129: The moment JavaScript library dependency for the frontend user interface was upgraded to remediate this vulnerability.
CVE-2021-0341: The com.squareup.okhttp dependency for the frontend user interface was updated to remediate this possible improper certificate validation vulnerability.
CVE-2020-21469: The PostgreSQL dependency was updated to remediate this possible Denial of Service (DoS) vulnerability.
GHSA-v78c-4p63-2j6c: The moment-timezone dependency for the frontend user interface was updated to remediate this vulnerability.
GHSA-xpw8-rcwv-8f8p: The Netty dependency for the frontend user interface was updated to remediate this possible HTTP/2 Rapid Reset Attack vulnerability.
The Eclipse Jetty dependency for the frontend user interface was updated to remediate the following vulnerabilities:
GHSA-jjjh-jjxp-wpff, GHSA-rgv9-q543-rqg4, GHSA-wgh7-54f2-x98r, GHSA-58qw-p7qm-5rvh, CVE-2022-2191, CVE-2022-25647, CVE-2007-1652, CVE-2022-2048, CVE-2009-5045, CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2017-9735, CVE-2022-2048, CVE-2020-27216, CVE-2023-44487, CVE-2023-40167, CVE-2023-36478, CVE-2023-36479, and CVE-2023-41900.
SONATYPE-2022-4402: The Postgres JDBC driver was updated to remediate this possible SQL injection vulnerability.
SONATYPE-2022-6438: The jackson-core and jackson-databind dependencies were updated to version 2.14.1 to remediate this vulnerability.
Graph Lakehouse 3.0.0
- CVE-2023-32067: The c-ares dependency library was updated to remediate a possible Denial of Service (DoS) vulnerability.
- CVE-2023-30535: The Snowflake JDBC driver was updated to version 3.13.29 to remediate a possible command injection vulnerability.
- CVE-2023-1370: The json-smart dependency for the frontend user interface was updated to remediate a possible stack overflow vulnerability.
- CVE-2022-2191: The Eclipse Jetty dependency for the frontend user interface was updated to version 11.0.14 to remediate this vulnerability.
- CVE-2022-46175: The JSON5 dependency for the frontend user interface was updated to remediate this vulnerability.
- CVE-2022-31129: The moment JavaScript library dependency for the frontend user interface was upgraded to remediate this vulnerability.
- CVE-2021-0341: The com.squareup.okhttp dependency for the frontend user interface was updated to remediate this possible improper certificate validation vulnerability.
- GHSA-v78c-4p63-2j6c: The moment-timezone dependency for the frontend user interface was updated to remediate this vulnerability.
- SONATYPE-2022-4402: The Postgres JDBC driver was updated to remediate this possible SQL injection vulnerability.
- SONATYPE-2022-6438: The jackson-core and jackon-databind dependencies were updated to version 2.14.1 to remediate this vulnerability.
AnzoGraph 2.5.23
CVE-2025-52999: The jackson-core dependency was updated to remediate a potential Denial-of-Service vulnerability.
CVE-2025-24970, CVE-2024-29025, CVE-2025-25193, CVE-2024-47535, CVE-2023-34462: The Netty library dependency for GDI and the front-end user interface was updated to remediate this vulnerability.
CVE-2024-45338: The golang.org/x/net html package dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
CVE-2020-13956: The org.apache.httpcomponents package dependency was updated to remediate this vulnerability.
SONATYPE-2012-0050: The Apache commons-codec package was updated to remediate this vulnerability.
CVE-2023-35116: The jackson-databind dependency was updated to remediate this vulnerability.
CVE-2024-43382: The Snowflake JDBC driver was updated to remediate this security setting vulnerability.
CVE-2024-48910, CVE-2024-45801: The DOMPurify JavaScript library was updated to remediate this vulnerability, preventing security bypasses and unauthorized modifications of application behavior.
CVE-2024-43591: The Azure CLI and Azure Service Connector was updated to remediate this Azure Command Line Integration (CLI) Elevation of Privilege vulnerability.
CVE-2024-47554: The Apache Commons IO dependency was updated to address this potential Denial of Service (DoS) vulnerability.
CVE-2024-8184: The Eclipse Jetty dependency for the frontend user interface was updated to remediate a potential Denial of Service (DoS) vulnerability.
CVE-2024-34156: The encoding/gob package of the Golang standard library was updated to remediate a potential Denial of Service (DoS) vulnerability.
CVE-2024-7254: The protobuf dependency for the frontend user interface was updated to address this potential Denial of Service (DoS) vulnerability.
CVE-2019-5827, CVE-2014-3566: The nss, nss-tools, sqlite, and nss-sysinit libraries were updated to remediate these vulnerabilities.
CVE-2025-22871: The golang net/http package dependency for azg cli was updated to remediate this HTTP request smuggling vulnerability.
CVE-2025-22872: The golang x/net/html package dependency for azg cli was updated to remediate this vulnerability.
CVE-2025-27553: The Apache Commons VFS dependency was updated to remediate this Relative Path Traversal vulnerability.
CVE-2025-0665, CVE-2025-0725, CVE-2024-2398: The libcurl library dependency was upgraded to version 8.12.0 to remediate this vulnerability.
CVE-2023-2976, CVE-2020-8908: The Google Guava library dependency was updated to remediate these vulnerabilities.
AnzoGraph 2.5.22
- CVE-2022-30187: Azure Storage client library dependencies were updated to remediate the Azure Storage Library Information Disclosure Vulnerability.
- CVE-2023-2976: The Google Guava dependency was updated to remediate this vulnerability.
- CVE-2024-29025: The io.netty:netty-codec-http dependency was updated to remediate this HttpPostRequestDecoder out-of-memory vulnerability.
- CVE-2024-29131 and CVE-2024-29133: The Apache Commons Configuration dependency was updated to remediate this Out-of-bounds Write vulnerability.
- CVE-2023-52428: The Connect2id Nimbus JOSE+JWT dependency was updated to remediate a potential Denial of Service (DoS) vulnerability.
AnzoGraph 2.5.21
- CVE-2024-24790: The golang net/netip package dependency was updated to remediate this vulnerability.
- CVE-2023-45288: The golang net/http and x/net/http2 package dependencies were updated to remediate this HTTP/2 CONTINUATION Flood vulnerability.
- CVE-2023-45283: The golang path/filepath package dependency was updated to remediate this vulnerability.
- CVE-2024-24791: The golang net/http HTTP/1.1 client dependency for AnzoGraphDB and frontend user interface was updated to remediate a potential Denial of Service (DoS) vulnerability.
- GHSA-58qw-p7qm-5rvh: The Eclipse Jetty dependency was updated to remediate this XmlParser XML external entity (XXE) vulnerability.
- CVE-2022-36944: The Scala dependency for AnzoGraphDB was upgraded to remediate this vulnerability.
AnzoGraph 2.5.20
- CVE-2023-3138: The libX11 dependency for the frontend user interface was updated to remediate this vulnerability.
- CVE-2023-46234: The cryptographic signature verification issue caused by the browserify-sign package dependency for the frontend user interface was remediated.
- CVE-2024-21634: The ion-java dependency for AnzoGraphDB was updated to remediate this vulnerability.
- CVE-2024-26308 and CVE-2024-25710: The Apache Commons Compress dependencies for AnzoGraphDB were updated to remediate these vulnerabilities.
- GHSA-xpw8-rcwv-8f8p: The netty-codec-http2 dependency for AnzoGraphDB and frontend user interface was updated to remediate the HTTP/2 Rapid Reset Attack vulnerability.
- CVE-2022-21698, CVE-2023-39325, CVE-2021-44716, CVE-2022-32149, CVE-2022-28948, CVE-2022-27664, and CVE-2022-41723: The golang dependencies for the AnzoGraph operator (client_golang, net/http, golang.org/x/net/http2, Go-Yaml) were updated to remediate these vulnerabilities.
- GHSA-m425-mq94-257g: The gRPC-Go dependency for the AnzoGraph (golang) client was updated to remediate the HTTP/2 Rapid Reset Attack vulnerability.
- CVE-2023-46233: The configuration of crypto-js JavaScript library for the frontend user interface was updated to remediate this vulnerability.
- CVE-2024-22201, CVE-2024-25710, CVE-2024-26308, and CVE-2023-32200: The Eclipse Jetty, Apache Commons Compress, and Apache Jena dependencies for the frontend user interface were updated to remediate these vulnerabilities.
- CVE-2024-29857 and CVE-2024-30172: The BC Java, BC Java LTS, BC-FJA, and BC C# .Net dependencies for the frontend user interface were updated to remediate these vulnerabilities.
- CVE-2024-33601, CVE-2024-33599, CVE-2024-33600, CVE-2024-33602, CVE-2024-2961, CVE-2023-4813, CVE-2023-4806, CVE-2023-4527, and CVE-2023-4911: The glibc library dependencies for all containers were updated to remediate these vulnerabilities.
AnzoGraph 2.5.19
The Jetty dependency for the frontend user interface was updated to remediate the following vulnerabilities:
GHSA-jjjh-jjxp-wpff, GHSA-rgv9-q543-rqg4, GHSA-wgh7-54f2-x98r, GHSA-58qw-p7qm-5rvh, CVE-2022-25647, CVE-2007-1652, CVE-2022-2048, CVE-2009-5045, CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2017-9735, CVE-2022-2048, CVE-2020-27216, CVE-2023-44487, CVE-2023-40167, CVE-2023-36478, CVE-2023-36479, and CVE-2023-41900.
AnzoGraph 2.5.17
- CVE-2023-30535: The Snowflake JDBC driver was updated to version 3.13.29 to remediate a possible command injection vulnerability.
AnzoGraph 2.5.15
- CVE-2023-28154: The Webpack dependency for the frontend user interface was updated to remediate this vulnerability.
- CVE-2023-1370: The json-smart dependency for the frontend user interface was updated to remediate a possible stack overflow vulnerability.
AnzoGraph 2.5.14
- CVE-2022-2191: The Eclipse Jetty dependency for the frontend user interface was updated to version 11.0.14 to remediate this vulnerability.
AnzoGraph 2.5.13
- SONATYPE-2020-0352, SONATYPE-2021-0246, and CVE-2020-7760: The codemirror dependency was updated to remediate these vulnerabilities.
- GHSA-wc69-rhjr-hc9g, GHSA-8hfj-j24r-96c4, CVE-2022-24785, and CVE-2022-31129: The moment dependency was updated to remediate these vulnerabilities.
AnzoGraph 2.5.12
- SONATYPE-2022-6438: The jackson-core and jackon-databind dependencies were updated to version 2.14.1 to remediate this vulnerability.
- GHSA-h4h5-3hr4-j3g2: The com.google.protobuf and woodstox-core dependencies were updated to remediate this vulnerability.
AnzoGraph 2.5.11
- CVE-2022-42889: The Apache Commons Text (commons-text) dependency was updated to remediate this vulnerability.
- CVE-2022-42003 and CVE-2022-42004: The FasterXML jackson-databind dependencies were updated to remediate these vulnerabilities.
- CVE-2022-41853: To mitigate this vulnerability, the HyperSQL DataBase driver was removed from the product.
- CVE-2022-36944: The Scala library was updated to version 2.13.9 to remediate this vulnerability.
- CVE-2020-15250: The JUnit dependency was updated to version 4.13.1 to remediate this vulnerability.
AnzoGraph 2.5.10
- CVE-2015-6420: The Apache Commons Collections (ACC) library (commons-collections) dependency was updated to remediate this vulnerability.
- CVE-2022-25168: The Apache Hadoop file utility (hadoop-common) dependency was updated to remediate this vulnerability.
- CVE-2022-2309: The python2-lxml dependency was updated to remediate this vulnerability.
AnzoGraph 2.5.8
- CVE-2022-31129: The moment JavaScript library dependency in the AnzoGraph user interface was upgraded to remediate this vulnerability.
AnzoGraph 2.5.7
- CVE-2021-0341: The unused Java component OkHostnameVerifier.java was removed from the AnzoGraph user interface to remediate this vulnerability.
AnzoGraph 2.5.6
- CVE-2020-8908: Updated the GDI Guava dependency to remediate a temp directory creation vulnerability.
- CVE-2021-22573: Updated the GDI com.google.oauth-client:google-oauth-client dependency to version 1.33.3 to remediate a vulnerability where the IDToken verifier did not verify if a token was properly signed.
- CVE-2022-24823: Updated the GDI Netty IO dependency to version 4.1.77.Final to remediate this vulnerability.
AnzoGraph 2.5.5
- CVE-2020-36518: The jackson-databind dependency for AnzoGraph extensions and the frontend user interface was updated to remediate a Java StackOverflow exception and Denial of Service (DoS) vulnerability.
AnzoGraph 2.5.4
- CVE-2021-3807: The ansi-regex dependency in the frontend user interface was updated to remediate an Inefficient Regular Expression Complexity vulnerability.
- CVE-2022-0778: The MySQL driver was updated to remediate a Denial of Service (DoS) vulnerability related to certificate parsing.
- CVE-2022-29078: The Embedded JavaScript templates package for Node.js, which is used in the frontend user interface, was updated to remediate a vulnerability that could allow server-side template injection.
AnzoGraph 2.5.3
- CVE-2022-24785: The Moment.js JavaScript date library frontend user interface dependency was updated to remediate a path traversal vulnerability.
- CVE-2020-15366, CVE-2021-3757, CVE-2021-3918, CVE-2021-23807: The Another JSON Schema Validator (AJV), json-schema, jsonpointer, and immer frontend user interface dependencies were updated to remediate "prototype pollution" vulnerabilities.
- CVE-2021-23364, CVE-2021-27290, and CVE-2021-23382: The package browserslist, ssri, and postcss frontend user interface dependencies were updated to remediate a Regular Expression Denial of Service (ReDoS) vulnerability.
- CVE-2021-3803: The nth-check frontend user interface dependency was updated to remediate an Inefficient Regular Expression Complexity vulnerability.
AnzoGraph 2.5.2
- CVE-2020-36518: The jackson-databind dependency in the GDI and Neptune and Geospatial extensions was updated to remediate a Java StackOverflow exception and Denial of Service (DoS) vulnerability.
- CVE-2021-3807 and CVE-2021-44906: The ansi-regex and Minimist dependencies in the AnzoGraph frontend container were updated to remediate vulnerabilities.
- CVE-2022-25315: The Expat library for Red Hat Enterprise Linux and CentOS 7 was updated to remediate the integer overflow flaw in libexpat.
AnzoGraph 2.5.1
Updated 2.5.1 Docker Images
The following Docker images were re-released to resolve the vulnerabilities listed below:
docker.io/cambridgesemantics/anzograph-frontend:latest docker.io/cambridgesemantics/anzograph-frontend:2.5.1-i202202151912-b202202242300 docker.io/cambridgesemantics/anzograph-frontend:2.5.1-i202202151912 docker.io/cambridgesemantics/anzograph-frontend:2.5.1 docker.io/cambridgesemantics/anzograph-db:latest docker.io/cambridgesemantics/anzograph-db:2.5.1-r202202161817-b202202242300 docker.io/cambridgesemantics/anzograph-db:2.5.1-r202202161817 docker.io/cambridgesemantics/anzograph-db:2.5.1 docker.io/cambridgesemantics/anzograph:latest docker.io/cambridgesemantics/anzograph:2.5.1-r202202161817-b202202242300 docker.io/cambridgesemantics/anzograph:2.5.1-r202202161817 docker.io/cambridgesemantics/anzograph:2.5.1 docker.io/cambridgesemantics/anzograph-devel:latest docker.io/cambridgesemantics/anzograph-devel:2.5.1-r202202161817-b202202242300 docker.io/cambridgesemantics/anzograph-devel:2.5.1-r202202161817 docker.io/cambridgesemantics/anzograph-devel:2.5.1
- CVE-2022-24407: The Cyrus SASL dependency was upgraded to remediate a flaw found in the SQL plugin.
- CVE-2020-25709: The OpenLDAP dependency was upgraded to remediate a vulnerability that could allow an attacker to send a malicious packet to be processed by OpenLDAP’s slapd server.
Released 2.5.1 Red Hat Marketplace Images
The following release of Red Hat Marketplace images resolve the vulnerabilities listed below:
cambridgesemantics/anzograph-frontend:2.5.1-i202202151912 cambridgesemantics/anzograph-db:2.5.1-r202202161817-b202202282115 cambridgesemantics/anzograph:2.5.1-r202202161817-b202202282115
- CVE-2022-24407: The Cyrus SASL dependency was upgraded to remediate a flaw found in the SQL plugin.
- CVE-2020-25709: The OpenLDAP dependency was upgraded to remediate a vulnerability that could allow an attacker to send a malicious packet to be processed by OpenLDAP’s slapd server.
Initial 2.5.1 Release of all Deployment Methods Except Red Hat Marketplace
- CVE-2021-21290, CVE-2021-37137, CVE-2021-21409, CVE-2021-37136, CVE-2021-21295, and CVE-2021-43797: The Netty dependencies were upgraded to remediate the listed vulnerabilities.
- CVE-2021-44832: The Apache Log4j 2 Java library was upgraded to version 2.17.1 to remediate a vulnerability related to a remote code execution (RCE) attack.
- CVE-2021-22569: The protobuf-java dependency was upgraded to remediate a potential Denial of Service (DoS) vulnerability.
- CVE-2021-3712: The OpenSSL library dependencies were updated to remediate a potential Denial of Service (DoS) vulnerability.
- CVE-2020-25704, CVE-2020-36322, and CVE-2021-42739: The Linux kernel headers dependency was upgraded to remediate a heap-based buffer overflow flaw related to kernel drivers.
Source: https://docs.sw.siemens.com/documentation/external/PL20260212925461721/en-US/graph_studio/relnotes/security-patches-azg.htm · retrieved 2026-08-23