Uploaded image for project: 'JOC - JS7 Operations Center'
  1. JOC - JS7 Operations Center
  2. JOC-2216

Upgrade bouncycastle to version 1.84 due to 3rd-party vulnerabilities CVE-2026-3505, CVE-2026-5598

    XMLWordPrintable

Details

    • Fix
    • Status: Released (View Workflow)
    • Minor
    • Resolution: Fixed
    • 2.5.13, 2.7.8, 2.8.3
    • 2.5.14, 2.9.0, 2.7.9, 2.8.4
    • None
    • None
    • CVE-2026-3505, CVE-2026-5598

    Description

      Current Situation

      Currently JS7 components Controller, Agent and JOC Cockpit ship with bouncycastle libraries 1.81 (2.5.x and 2.7.x releases) and 1.82 (2.8.x releases). These libraries are affected by the vulnerability.

      Currently we rate the impact of the vulnerability to be low. Also, no official impact rating has been publicly provided yet.

      Desired Behavior

      JS7 components Controller, Agent and JOC Cockpit should ship with bouncycastle version 1.84 that fixes the issue.

      Immediate Measures

      Customers can replace the existing bouncycastle libraries with the current version of these libraries.

      Releases 2.5.x 

      Releases 2.7.x and 2.8.x

      Attachments

        Activity

          People

            sp Santiago Aucejo Petzoldt
            sp Santiago Aucejo Petzoldt
            Ajay Kumbhkar Ajay Kumbhkar
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: