3.4 - Security fixes


Security fixes provided in 3.4.0-funcrel

CAST service CVE Severity Description Affected CAST release
admin-center CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload 3.3.0
admin-center CVE-2025-49146 pgjdbc: pgjdbc insecure authentication in channel binding 3.3.0
analysis-node CVE-2025-48734 commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum’s declaredClass property by default 3.3.0
analysis-node CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload 3.3.0
analysis-node CVE-2025-49146 pgjdbc: pgjdbc insecure authentication in channel binding 3.3.0
auth-service CVE-2025-41235 Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies 3.3.0
console CVE-2025-41235 Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies 3.3.0
dashboards CVE-2025-22235 org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed 3.3.0
dashboards CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload 3.3.0
dashboards CVE-2025-49146 pgjdbc: pgjdbc insecure authentication in channel binding 3.3.0
gateway CVE-2025-41235 Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies 3.3.0
gateway CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload 3.3.0
imaging-viewer CVE-2025-4565 python-protobuf: Unbounded recursion in Python Protobuf 3.3.0
neo4j CVE-2025-1948 jetty-http2-common: Jetty HTTP/2 Header List Size Vulnerability 3.3.0
sso-service CVE-2025-3501 org.keycloak.protocol.services: Keycloak hostname verification 3.3.0