Skip to content

Commit c3013af

Browse files
committed
OpenIG 6.0.2 Released, OpenIDM 7.0.2 Released
1 parent d901494 commit c3013af

2 files changed

Lines changed: 49 additions & 0 deletions

File tree

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
---
2+
layout: home
3+
landing-title: "OpenIDM 7.0.2 Released"
4+
landing-title2: "OpenIDM 7.0.2 Released"
5+
description: OpenIDM 7.0.2 with security updates and dependency improvements
6+
keywords: 'OpenIDM, identity management, release, 7.0.2, security update, CVE-2025-25247'
7+
imageurl: 'openidm-og.png'
8+
share-buttons: true
9+
---
10+
# OpenIDM 7.0.2 Released
11+
[Download](https://github.com/OpenIdentityPlatform/OpenIDM/releases/tag/7.0.2)
12+
13+
## What's new
14+
* [CVE-2025-25247](https://nvd.nist.gov/vuln/detail/CVE-2025-25247) - Apache Felix Webconsole XSS vulnerability in services console
15+
* Updated org.openidentityplatform.openicf dependency to version 2.0.2
16+
17+
Full changeset ([more details](https://github.com/OpenIdentityPlatform/OpenIDM/compare/7.0.1...7.0.2))
18+
19+
## Thanks for the contributions
20+
<i id="vharseko"><i>1. <a href="https://github.com/vharseko" target="_blank">vharseko</a></i>
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
---
2+
layout: home
3+
landing-title: "OpenIG 6.0.2 Released"
4+
landing-title2: "OpenIG 6.0.2 Released"
5+
description: OpenIG 6.0.2 with critical security updates and bug fixes
6+
keywords: 'OpenIG, identity gateway, reverse proxy, release, 6.0.2, security update, CVE-2024-56128, CVE-2025-27818, CVE-2025-27819, CVE-2025-13465'
7+
imageurl: 'openig-og.png'
8+
share-buttons: true
9+
---
10+
# OpenIG 6.0.2 Released
11+
[Download](https://github.com/OpenIdentityPlatform/OpenIG/releases/tag/6.0.2)
12+
13+
## What's new
14+
15+
* Fixed ESAPI initialisation error
16+
* Updated OpenAM to version 16.0.5
17+
* Addressed critical vulnerabilities:
18+
* [CVE-2024-56128](https://nvd.nist.gov/vuln/detail/CVE-2024-56128), [CVE-2025-27818](https://nvd.nist.gov/vuln/detail/CVE-2025-27818), and [CVE-2025-27819](https://nvd.nist.gov/vuln/detail/CVE-2025-27819) - Apache Kafka Deserialization of Untrusted Data vulnerability and Incorrectly Implements Authentication Algorithm
19+
* [CVE-2025-13465](https://nvd.nist.gov/vuln/detail/CVE-2025-13465) - Lodash Prototype Pollution vulnerability in `_.unset` and `_.omit` functions
20+
21+
Full changeset ([more details](https://github.com/OpenIdentityPlatform/OpenIG/compare/6.0.1...6.0.2))
22+
23+
## Thanks for the contributions
24+
25+
<i id="vharseko"><i>1. <a href="https://github.com/vharseko" target="_blank">vharseko</a></i>
26+
27+
<i id="maximthomas"><i>2. <a href="https://github.com/maximthomas" target="_blank">maximthomas</a></i>
28+
29+
<i id="dependabot"><i>3. <a href="https://github.com/dependabot" target="_blank">dependabot</a></i>

0 commit comments

Comments
 (0)