Resolved Security Issues in Release 23.5.30-PCE
This section provides important security information for this release.
See 2023 Security Advisories for more information.
See 2024 Security Advisories for more information.
redis
was upgraded to 6.2.16 to address CVE-2024-31449.webrick
was upgraded to 1.8.2 to address CVE-2024-47220curl
was upgraded to v8.8.0 to address CVE-2024-7264, CVE-2024-6197, CVE-2024-2466, CVE-2024-2398, CVE-2024-2379, and CVE-2024-2004.cgi-0.3.2.gem upgraded to v0.3.6 to address CVE-2021-33621: This CVE did not impact Illumio PCE.
globalid upgraded to v1.0.1: globalid upgraded to v1.0.1 to address CVE-2023-22799.
google-protobuf upgraded to v3.22.5: google-protobuf upgraded to v3.22.5 to address CVE-2022-3171 and CVE-2021-22569.
rack upgraded to v2.2.7: rack upgraded to v2.2.7 address CVE-2022-44572, CVE-2022-44571, CVE-2023-27530, CVE-2023-27539, and CVE-2022-44570.
rails, actionpack, activerecord, activesupport and related gems upgraded to v6.1.7.4: rails, actionpack, activerecord, activesupport and related gems upgraded to v6.1.7.4 to address multiple CVEs including CVE-2023-28120, CVE-2023-23913, CVE-2023-28362, CVE-2023-22792 CVE-2023-22795 CVE-2022-3704, CVE-2023-22794 CVE-2022-44566, and CVE-2023-22796.