Skip to main content

Illumio Core What's New and Release Notes for 23.5

Resolved Security Issues in Release 23.5.30-PCE

This section provides important security information for this release. 

  • redis was upgraded to 6.2.16 to address CVE-2024-31449.

  • webrick was upgraded to 1.8.2 to address CVE-2024-47220

  • curl was upgraded to v8.8.0 to address CVE-2024-7264, CVE-2024-6197, CVE-2024-2466, CVE-2024-2398, CVE-2024-2379, and CVE-2024-2004.

  • cgi-0.3.2.gem upgraded to v0.3.6 to address CVE-2021-33621: This CVE did not impact Illumio PCE.

  • globalid upgraded to v1.0.1: globalid upgraded to v1.0.1 to address CVE-2023-22799.

  • google-protobuf upgraded to v3.22.5: google-protobuf upgraded to v3.22.5 to address CVE-2022-3171 and CVE-2021-22569.

  • rack upgraded to v2.2.7: rack upgraded to v2.2.7 address CVE-2022-44572, CVE-2022-44571, CVE-2023-27530, CVE-2023-27539, and CVE-2022-44570.

  • rails, actionpack, activerecord, activesupport and related gems upgraded to v6.1.7.4: rails, actionpack, activerecord, activesupport and related gems upgraded to v6.1.7.4 to address multiple CVEs including CVE-2023-28120, CVE-2023-23913, CVE-2023-28362, CVE-2023-22792 CVE-2023-22795 CVE-2022-3704, CVE-2023-22794 CVE-2022-44566, and CVE-2023-22796.