Skip to main content
Skip table of contents

Release 3.3.1

Overview:

Build on the foundation of version 3.3.0, this version is mainly targeting security improvements and hardening of the stack by updating all components to their most recent versions. This update will resolve high and critical OWASP CVEs listed below in the Security section.

Majors dependencies upgrades:

  • Cassandra driver from 3.x to 4.x

  • Tomcat related libraries from 8.x to 9.x

  • Spring latest 5.x (5.3.27)

  • Spring boot 2.7.11

  • Zookeeper client 3.8.1

In terms of functionality, no new major code is introduced, only improvements for the new features introduced in 3.3.0:

  • Veridium Admin users can now be connected to Active Directory permissions, offering support for central point user configurations in terms of access

  • FIDO enrolments are available again for Android Platform authenticator and Windows 11 TPM authenticator with EC attestation.

  • Lost mode is now also available for users that don’t have any other Phone or Hardware Token enroled.

  • Improvements in Veridium Manager access permissions for GUI that clean up logs and browser console errors for limited permission accounts.

  • Email notifications now contain detailed authenticator names for all scenarios.

  • Improved elements' display in various GUI sections to increase readability, correct typos and mitigate overlapping graphics.

  • Audit Administrators column translates all SIDs in email addresses for improved readability and tracking.

  • URLs containing “-” in their last part are now treated correctly by websecadmin

  • Improved permission granularity for limited accounts by introducing View AD details , View location , View UBA info ,View history details, to better comply with privacy regulated scenarios. This is especially helpful in deciding which part of the admin team has access to sensitive data (i.e. Support role can be configured to hide Directory Service Info, Location, UBA or History if it’s not needed)

Security improvements:

Admin CVEs

Dependency

Vulnerability IDs

Severity

log4j-jul-2.11.2.jar

cpe:2.3:a:apache:log4j:2.11.2:*:*:*:*:*:*:*

CRITICAL

tomcat-util-scan-8.5.31.jar

cpe:2.3:a:apache:tomcat:8.5.31:*:*:*:*:*:*:*
cpe:2.3:a:apache_tomcat:apache_tomcat:8.5.31:*:*:*:*:*:*:*

CRITICAL

tomcat-util-8.5.31.jar

cpe:2.3:a:apache:tomcat:8.5.31:*:*:*:*:*:*:*
cpe:2.3:a:apache_tomcat:apache_tomcat:8.5.31:*:*:*:*:*:*:*

CRITICAL

tomcat-jsp-api-8.5.31.jar

cpe:2.3:a:apache:tomcat:8.5.31:*:*:*:*:*:*:*

CRITICAL

tomcat-jaspic-api-8.5.31.jar

cpe:2.3:a:apache:tomcat:8.5.31:*:*:*:*:*:*:*

CRITICAL

tomcat-coyote-8.5.31.jar

cpe:2.3:a:apache:tomcat:8.5.31:*:*:*:*:*:*:*
cpe:2.3:a:apache_tomcat:apache_tomcat:8.5.31:*:*:*:*:*:*:*

CRITICAL

tomcat-catalina-8.5.31.jar

cpe:2.3:a:apache:tomcat:8.5.31:*:*:*:*:*:*:*
cpe:2.3:a:apache_tomcat:apache_tomcat:8.5.31:*:*:*:*:*:*:*

CRITICAL

tomcat-api-8.5.31.jar

cpe:2.3:a:apache:tomcat:8.5.31:*:*:*:*:*:*:*
cpe:2.3:a:apache_tomcat:apache_tomcat:8.5.31:*:*:*:*:*:*:*

CRITICAL

spring-webmvc-5.1.19.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.19:release:*:*:*:*:*:*

CRITICAL

spring-web-5.1.19.RELEASE.jar

cpe:2.3:a:springsource:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:web_project:web:5.1.19:release:*:*:*:*:*:*

HIGH

spring-tx-5.1.16.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.16:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.16:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.16:release:*:*:*:*:*:*

CRITICAL

spring-tx-5.1.0.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.0:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.0:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.0:release:*:*:*:*:*:*

CRITICAL

spring-security-web-5.1.13.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_security:5.1.13:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:5.1.13:release:*:*:*:*:*:*
cpe:2.3:a:web_project:web:5.1.13:release:*:*:*:*:*:*

CRITICAL

spring-security-crypto-5.1.5.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_security:5.1.5:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:5.1.5:release:*:*:*:*:*:*

CRITICAL

spring-security-core-5.1.13.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_security:5.1.13:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:5.1.13:release:*:*:*:*:*:*

CRITICAL

spring-security-config-5.1.13.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_security:5.1.13:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:5.1.13:release:*:*:*:*:*:*

CRITICAL

spring-messaging-5.1.16.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.16:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.16:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.16:release:*:*:*:*:*:*

CRITICAL

spring-jcl-5.1.19.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.19:release:*:*:*:*:*:*

CRITICAL

spring-expression-5.1.19.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.19:release:*:*:*:*:*:*

CRITICAL

spring-core-5.1.19.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.19:release:*:*:*:*:*:*

CRITICAL

spring-context-5.1.19.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.19:release:*:*:*:*:*:*

CRITICAL

spring-beans-5.1.19.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.19:release:*:*:*:*:*:*

CRITICAL

spring-aop-5.1.19.RELEASE.jar

cpe:2.3:a:pivotal_software:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:springsource:spring_framework:5.1.19:release:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:5.1.19:release:*:*:*:*:*:*

CRITICAL

solr-solrj-6.2.1.jar

cpe:2.3:a:apache:solr:6.2.1:*:*:*:*:*:*:*

CRITICAL

snakeyaml-1.30.jar

cpe:2.3:a:snakeyaml_project:snakeyaml:1.30:*:*:*:*:*:*:*
cpe:2.3:a:yaml_project:yaml:1.30:*:*:*:*:*:*:*

CRITICAL

jetty-util-9.2.25.v20180606.jar

cpe:2.3:a:eclipse:jetty:9.2.25:20180606:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty:9.2.25:20180606:*:*:*:*:*:*
cpe:2.3:a:mortbay_jetty:jetty:9.2.25:20180606:*:*:*:*:*:*

CRITICAL

jetty-io-9.2.25.v20180606.jar

cpe:2.3:a:eclipse:jetty:9.2.25:20180606:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty:9.2.25:20180606:*:*:*:*:*:*
cpe:2.3:a:mortbay_jetty:jetty:9.2.25:20180606:*:*:*:*:*:*

CRITICAL

jetty-http-9.2.25.v20180606.jar

cpe:2.3:a:eclipse:jetty:9.2.25:20180606:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty:9.2.25:20180606:*:*:*:*:*:*
cpe:2.3:a:mortbay_jetty:jetty:9.2.25:20180606:*:*:*:*:*:*

CRITICAL

jetty-client-9.2.25.v20180606.jar

cpe:2.3:a:eclipse:jetty:9.2.25:20180606:*:*:*:*:*:*
cpe:2.3:a:jetty:jetty:9.2.25:20180606:*:*:*:*:*:*
cpe:2.3:a:mortbay_jetty:jetty:9.2.25:20180606:*:*:*:*:*:*

CRITICAL

jackson-mapper-asl-1.9.13.jar

cpe:2.3:a:fasterxml:jackson-mapper-asl:1.9.13:*:*:*:*:*:*:*

HIGH

esapi-2.1.0.1.jar

cpe:2.3:a:owasp:enterprise_security_api:2.1.0.1:*:*:*:*:*:*:*

CRITICAL

commons-fileupload-1.3.1.jar

cpe:2.3:a:apache:commons_fileupload:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_net:1.3.1:*:*:*:*:*:*:*

CRITICAL

batik-util-1.8.jar

cpe:2.3:a:apache:batik:1.8:*:*:*:*:*:*:*

CRITICAL

batik-ext-1.8.jar

cpe:2.3:a:apache:batik:1.8:*:*:*:*:*:*:*

CRITICAL

batik-css-1.8.jar

cpe:2.3:a:apache:batik:1.8:*:*:*:*:*:*:*

CRITICAL

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.