Skip to content

Commit 859a194

Browse files
JoelBergstrandinjectivesLojjs
authored
CVE 2025 48924 release (#809)
Co-authored-by: Dmitriy Tverdiakov <11927660+injectives@users.noreply.github.com> Co-authored-by: Louise Berglund <louise.berglund@neo4j.com>
1 parent be8f1e4 commit 859a194

File tree

9 files changed

+213
-306
lines changed

9 files changed

+213
-306
lines changed

LICENSES.txt

Lines changed: 35 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -24,9 +24,9 @@ Apache-2.0
2424
aws-java-sdk-core-1.12.643.jar
2525
aws-java-sdk-kms-1.12.643.jar
2626
aws-java-sdk-s3-1.12.643.jar
27-
byte-buddy-1.15.11.jar
28-
byte-buddy-agent-1.15.11.jar
29-
caffeine-3.2.0.jar
27+
byte-buddy-1.17.5.jar
28+
byte-buddy-agent-1.17.5.jar
29+
caffeine-3.2.1.jar
3030
cassandra-driver-core-3.10.0.jar
3131
commons-beanutils-1.9.4.jar
3232
commons-cli-1.5.0.jar
@@ -37,6 +37,8 @@ Apache-2.0
3737
commons-csv-1.9.0.jar
3838
commons-daemon-1.0.13.jar
3939
commons-io-2.19.0.jar
40+
commons-lang-2.6.jar
41+
commons-lang3-3.17.0.jar
4042
commons-lang3-3.18.0.jar
4143
commons-logging-1.3.5.jar
4244
commons-math3-3.6.1.jar
@@ -121,24 +123,24 @@ Apache-2.0
121123
jcip-annotations-1.0-1.jar
122124
jctools-core-4.0.5.jar
123125
jettison-1.5.4.jar
124-
jetty-alpn-java-server-12.0.16.jar
125-
jetty-alpn-server-12.0.16.jar
126-
jetty-ee-12.0.16.jar
127-
jetty-ee8-nested-12.0.16.jar
128-
jetty-ee8-security-12.0.16.jar
129-
jetty-ee8-servlet-12.0.16.jar
130-
jetty-ee8-webapp-12.0.16.jar
131-
jetty-http-12.0.16.jar
132-
jetty-http2-common-12.0.16.jar
133-
jetty-http2-hpack-12.0.16.jar
134-
jetty-http2-server-12.0.16.jar
135-
jetty-io-12.0.16.jar
136-
jetty-security-12.0.16.jar
137-
jetty-server-12.0.16.jar
126+
jetty-alpn-java-server-12.0.17.jar
127+
jetty-alpn-server-12.0.17.jar
128+
jetty-ee-12.0.17.jar
129+
jetty-ee8-nested-12.0.17.jar
130+
jetty-ee8-security-12.0.17.jar
131+
jetty-ee8-servlet-12.0.17.jar
132+
jetty-ee8-webapp-12.0.17.jar
133+
jetty-http-12.0.17.jar
134+
jetty-http2-common-12.0.17.jar
135+
jetty-http2-hpack-12.0.17.jar
136+
jetty-http2-server-12.0.17.jar
137+
jetty-io-12.0.17.jar
138+
jetty-security-12.0.17.jar
139+
jetty-server-12.0.17.jar
138140
jetty-servlet-api-4.0.6.jar
139-
jetty-session-12.0.16.jar
140-
jetty-util-12.0.16.jar
141-
jetty-xml-12.0.16.jar
141+
jetty-session-12.0.17.jar
142+
jetty-util-12.0.17.jar
143+
jetty-xml-12.0.17.jar
142144
jffi-1.2.16-native.jar
143145
jffi-1.2.16.jar
144146
jmespath-java-1.12.643.jar
@@ -239,7 +241,7 @@ Apache-2.0
239241
perfmark-api-0.27.0.jar
240242
picocli-4.7.7.jar
241243
proto-google-common-protos-2.51.0.jar
242-
reactor-core-3.6.16.jar
244+
reactor-core-3.6.18.jar
243245
reload4j-1.2.22.jar
244246
scala-collection-contrib_2.13-0.3.0.jar
245247
scala-library-2.13.16.jar
@@ -2222,14 +2224,14 @@ Eclipse Public License - v 2.0
22222224
jersey-container-servlet-core-2.43.jar
22232225
jersey-hk2-2.43.jar
22242226
jersey-server-2.43.jar
2225-
junit-jupiter-5.12.2.jar
2226-
junit-jupiter-api-5.12.2.jar
2227-
junit-jupiter-engine-5.12.2.jar
2228-
junit-jupiter-params-5.12.2.jar
2229-
junit-platform-commons-1.12.2.jar
2230-
junit-platform-engine-1.12.2.jar
2231-
junit-platform-launcher-1.12.2.jar
2232-
junit-platform-testkit-1.12.2.jar
2227+
junit-jupiter-5.13.1.jar
2228+
junit-jupiter-api-5.13.1.jar
2229+
junit-jupiter-engine-5.13.1.jar
2230+
junit-jupiter-params-5.13.1.jar
2231+
junit-platform-commons-1.13.1.jar
2232+
junit-platform-engine-1.13.1.jar
2233+
junit-platform-launcher-1.13.1.jar
2234+
junit-platform-testkit-1.13.1.jar
22332235
osgi-resource-locator-1.0.3.jar
22342236
------------------------------------------------------------------------------
22352237

@@ -2910,11 +2912,11 @@ and/or involve the use of third party software.
29102912
------------------------------------------------------------------------------
29112913
MIT
29122914
bcpkix-jdk15on-1.70.jar
2913-
bcpkix-jdk18on-1.80.jar
2915+
bcpkix-jdk18on-1.81.jar
29142916
bcprov-jdk15on-1.70.jar
2915-
bcprov-jdk18on-1.80.jar
2917+
bcprov-jdk18on-1.81.jar
29162918
bcutil-jdk15on-1.70.jar
2917-
bcutil-jdk18on-1.80.jar
2919+
bcutil-jdk18on-1.81.jar
29182920
cassandra-1.20.2.jar
29192921
checker-qual-3.43.0.jar
29202922
couchbase-1.20.2.jar
@@ -2928,7 +2930,7 @@ MIT
29282930
jersey-hk2-2.43.jar
29292931
jnr-x86asm-1.0.2.jar
29302932
localstack-1.20.2.jar
2931-
mockito-core-5.17.0.jar
2933+
mockito-core-5.18.0.jar
29322934
mssql-jdbc-6.2.1.jre7.jar
29332935
mysql-1.20.2.jar
29342936
neo4j-1.20.2.jar

NOTICE.txt

Lines changed: 52 additions & 50 deletions
Original file line numberDiff line numberDiff line change
@@ -54,9 +54,9 @@ Apache-2.0
5454
aws-java-sdk-core-1.12.643.jar
5555
aws-java-sdk-kms-1.12.643.jar
5656
aws-java-sdk-s3-1.12.643.jar
57-
byte-buddy-1.15.11.jar
58-
byte-buddy-agent-1.15.11.jar
59-
caffeine-3.2.0.jar
57+
byte-buddy-1.17.5.jar
58+
byte-buddy-agent-1.17.5.jar
59+
caffeine-3.2.1.jar
6060
cassandra-driver-core-3.10.0.jar
6161
commons-beanutils-1.9.4.jar
6262
commons-cli-1.5.0.jar
@@ -67,6 +67,8 @@ Apache-2.0
6767
commons-csv-1.9.0.jar
6868
commons-daemon-1.0.13.jar
6969
commons-io-2.19.0.jar
70+
commons-lang-2.6.jar
71+
commons-lang3-3.17.0.jar
7072
commons-lang3-3.18.0.jar
7173
commons-logging-1.3.5.jar
7274
commons-math3-3.6.1.jar
@@ -151,24 +153,24 @@ Apache-2.0
151153
jcip-annotations-1.0-1.jar
152154
jctools-core-4.0.5.jar
153155
jettison-1.5.4.jar
154-
jetty-alpn-java-server-12.0.16.jar
155-
jetty-alpn-server-12.0.16.jar
156-
jetty-ee-12.0.16.jar
157-
jetty-ee8-nested-12.0.16.jar
158-
jetty-ee8-security-12.0.16.jar
159-
jetty-ee8-servlet-12.0.16.jar
160-
jetty-ee8-webapp-12.0.16.jar
161-
jetty-http-12.0.16.jar
162-
jetty-http2-common-12.0.16.jar
163-
jetty-http2-hpack-12.0.16.jar
164-
jetty-http2-server-12.0.16.jar
165-
jetty-io-12.0.16.jar
166-
jetty-security-12.0.16.jar
167-
jetty-server-12.0.16.jar
156+
jetty-alpn-java-server-12.0.17.jar
157+
jetty-alpn-server-12.0.17.jar
158+
jetty-ee-12.0.17.jar
159+
jetty-ee8-nested-12.0.17.jar
160+
jetty-ee8-security-12.0.17.jar
161+
jetty-ee8-servlet-12.0.17.jar
162+
jetty-ee8-webapp-12.0.17.jar
163+
jetty-http-12.0.17.jar
164+
jetty-http2-common-12.0.17.jar
165+
jetty-http2-hpack-12.0.17.jar
166+
jetty-http2-server-12.0.17.jar
167+
jetty-io-12.0.17.jar
168+
jetty-security-12.0.17.jar
169+
jetty-server-12.0.17.jar
168170
jetty-servlet-api-4.0.6.jar
169-
jetty-session-12.0.16.jar
170-
jetty-util-12.0.16.jar
171-
jetty-xml-12.0.16.jar
171+
jetty-session-12.0.17.jar
172+
jetty-util-12.0.17.jar
173+
jetty-xml-12.0.17.jar
172174
jffi-1.2.16-native.jar
173175
jffi-1.2.16.jar
174176
jmespath-java-1.12.643.jar
@@ -269,7 +271,7 @@ Apache-2.0
269271
perfmark-api-0.27.0.jar
270272
picocli-4.7.7.jar
271273
proto-google-common-protos-2.51.0.jar
272-
reactor-core-3.6.16.jar
274+
reactor-core-3.6.18.jar
273275
reload4j-1.2.22.jar
274276
scala-collection-contrib_2.13-0.3.0.jar
275277
scala-library-2.13.16.jar
@@ -380,23 +382,23 @@ Eclipse Public License - Version 1.0
380382
jetty-servlet-api-4.0.6.jar
381383

382384
Eclipse Public License - Version 2.0
383-
jetty-alpn-java-server-12.0.16.jar
384-
jetty-alpn-server-12.0.16.jar
385-
jetty-ee-12.0.16.jar
386-
jetty-ee8-nested-12.0.16.jar
387-
jetty-ee8-security-12.0.16.jar
388-
jetty-ee8-servlet-12.0.16.jar
389-
jetty-ee8-webapp-12.0.16.jar
390-
jetty-http-12.0.16.jar
391-
jetty-http2-common-12.0.16.jar
392-
jetty-http2-hpack-12.0.16.jar
393-
jetty-http2-server-12.0.16.jar
394-
jetty-io-12.0.16.jar
395-
jetty-security-12.0.16.jar
396-
jetty-server-12.0.16.jar
397-
jetty-session-12.0.16.jar
398-
jetty-util-12.0.16.jar
399-
jetty-xml-12.0.16.jar
385+
jetty-alpn-java-server-12.0.17.jar
386+
jetty-alpn-server-12.0.17.jar
387+
jetty-ee-12.0.17.jar
388+
jetty-ee8-nested-12.0.17.jar
389+
jetty-ee8-security-12.0.17.jar
390+
jetty-ee8-servlet-12.0.17.jar
391+
jetty-ee8-webapp-12.0.17.jar
392+
jetty-http-12.0.17.jar
393+
jetty-http2-common-12.0.17.jar
394+
jetty-http2-hpack-12.0.17.jar
395+
jetty-http2-server-12.0.17.jar
396+
jetty-io-12.0.17.jar
397+
jetty-security-12.0.17.jar
398+
jetty-server-12.0.17.jar
399+
jetty-session-12.0.17.jar
400+
jetty-util-12.0.17.jar
401+
jetty-xml-12.0.17.jar
400402

401403
Eclipse Public License - v 1.0
402404
eclipse-collections-11.1.0.jar
@@ -420,14 +422,14 @@ Eclipse Public License - v 2.0
420422
jersey-container-servlet-core-2.43.jar
421423
jersey-hk2-2.43.jar
422424
jersey-server-2.43.jar
423-
junit-jupiter-5.12.2.jar
424-
junit-jupiter-api-5.12.2.jar
425-
junit-jupiter-engine-5.12.2.jar
426-
junit-jupiter-params-5.12.2.jar
427-
junit-platform-commons-1.12.2.jar
428-
junit-platform-engine-1.12.2.jar
429-
junit-platform-launcher-1.12.2.jar
430-
junit-platform-testkit-1.12.2.jar
425+
junit-jupiter-5.13.1.jar
426+
junit-jupiter-api-5.13.1.jar
427+
junit-jupiter-engine-5.13.1.jar
428+
junit-jupiter-params-5.13.1.jar
429+
junit-platform-commons-1.13.1.jar
430+
junit-platform-engine-1.13.1.jar
431+
junit-platform-launcher-1.13.1.jar
432+
junit-platform-testkit-1.13.1.jar
431433
osgi-resource-locator-1.0.3.jar
432434

433435
GNU General Public License (GPL), version 2, with the Classpath exception
@@ -473,11 +475,11 @@ LGPL-2.1-or-later
473475

474476
MIT
475477
bcpkix-jdk15on-1.70.jar
476-
bcpkix-jdk18on-1.80.jar
478+
bcpkix-jdk18on-1.81.jar
477479
bcprov-jdk15on-1.70.jar
478-
bcprov-jdk18on-1.80.jar
480+
bcprov-jdk18on-1.81.jar
479481
bcutil-jdk15on-1.70.jar
480-
bcutil-jdk18on-1.80.jar
482+
bcutil-jdk18on-1.81.jar
481483
cassandra-1.20.2.jar
482484
checker-qual-3.43.0.jar
483485
couchbase-1.20.2.jar
@@ -491,7 +493,7 @@ MIT
491493
jersey-hk2-2.43.jar
492494
jnr-x86asm-1.0.2.jar
493495
localstack-1.20.2.jar
494-
mockito-core-5.17.0.jar
496+
mockito-core-5.18.0.jar
495497
mssql-jdbc-6.2.1.jre7.jar
496498
mysql-1.20.2.jar
497499
neo4j-1.20.2.jar

common/build.gradle

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,9 @@ dependencies {
6060
api('net.minidev:json-smart:2.5.2') {
6161
because 'CVE-2024-57699'
6262
}
63+
api('org.apache.commons:commons-lang3:3.18.0') {
64+
because 'CVE-2025-48924'
65+
}
6366
}
6467

6568
configurations.configureEach {

it/src/test/java/apoc/it/core/ExportCypherEnterpriseFeaturesTest.java

Lines changed: 8 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -59,31 +59,17 @@ public static void afterAll() {
5959
}
6060

6161
private static void beforeTwoLabelsWithOneCompoundConstraintEach() {
62-
session.writeTransaction(tx -> {
63-
tx.run("CREATE CONSTRAINT compositeBase FOR (t:Base) REQUIRE (t.tenantId, t.id) IS NODE KEY");
64-
tx.commit();
65-
return null;
66-
});
67-
session.writeTransaction(tx -> {
68-
tx.run("CREATE (a:Person:Base {name: 'Phil', surname: 'Meyer', tenantId: 'neo4j', id: 'waBfk3z'}) "
69-
+ "CREATE (b:Person:Base {name: 'Silvia', surname: 'Jones', tenantId: 'random', id: 'waBfk3z'}) "
70-
+ "CREATE (a)-[:KNOWS {foo:2}]->(b)");
71-
tx.commit();
72-
return null;
73-
});
62+
session.executeWriteWithoutResult(
63+
tx -> tx.run("CREATE CONSTRAINT compositeBase FOR (t:Base) REQUIRE (t.tenantId, t.id) IS NODE KEY"));
64+
session.executeWriteWithoutResult(tx ->
65+
tx.run("CREATE (a:Person:Base {name: 'Phil', surname: 'Meyer', tenantId: 'neo4j', id: 'waBfk3z'}) "
66+
+ "CREATE (b:Person:Base {name: 'Silvia', surname: 'Jones', tenantId: 'random', id: 'waBfk3z'}) "
67+
+ "CREATE (a)-[:KNOWS {foo:2}]->(b)"));
7468
}
7569

7670
private static void afterTwoLabelsWithOneCompoundConstraintEach() {
77-
session.writeTransaction(tx -> {
78-
tx.run("MATCH (a:Person:Base) DETACH DELETE a");
79-
tx.commit();
80-
return null;
81-
});
82-
session.writeTransaction(tx -> {
83-
tx.run("DROP CONSTRAINT compositeBase");
84-
tx.commit();
85-
return null;
86-
});
71+
session.executeWriteWithoutResult(tx -> tx.run("MATCH (a:Person:Base) DETACH DELETE a"));
72+
session.executeWriteWithoutResult(tx -> tx.run("DROP CONSTRAINT compositeBase"));
8773
}
8874

8975
@Test

0 commit comments

Comments
 (0)