Platform 2023.2.35 is a maintenance release that addresses security vulnerabilities in third-party dependencies across Operations Manager, NSO Service Manager, Core, Configuration Manager Enterprise, Automation Catalog, and other Platform components.
Security fixes (43)
This release includes security updates that address vulnerabilities in third-party packages and Platform components.
| Component | Feature | Description |
|---|---|---|
| Admin Essentials | Updated Admin Essentials security dependencies (ENG-28460) | Updated third-party dependencies in Admin Essentials, including axios, swagger-ui-react, fast-uri, immutable, js-yaml, and moment, to resolve security vulnerabilities. |
| Automation Catalog | Updated transitive dependencies (ENG-27985) | Updated transitive dependencies in Automation Catalog to resolve reported security vulnerabilities. |
| Automation Catalog | Updated a dependency to address a security vulnerability (ENG-28295, ENG-28296) | Updated a third-party dependency in Automation Catalog to address a security vulnerability. |
| Configuration Manager Enterprise | Resolved Snyk-reported vulnerabilities (ENG-26990, ENG-28147) | Resolved security vulnerabilities that Snyk reported in Configuration Manager Enterprise dependencies. |
| Configuration Manager Enterprise | Resolved a Snyk-reported vulnerability (ENG-28774) | Resolved a security vulnerability that Snyk reported in a Configuration Manager Enterprise dependency. |
| Core | Updated Core security dependencies (ENG-28459) | Updated axios, express, compression, moment, undici, brace-expansion, fast-uri, and js-yaml to resolve security vulnerabilities. |
| Core | Upgraded packages to address a security vulnerability (ENG-28461) | Upgraded moment, fast-uri, axios, and swagger-ui-react to address a security vulnerability. |
| Core | Updated the transitive fast-uri dependency (ENG-28464) | Updated the transitive fast-uri dependency to resolve a security vulnerability. |
| Core | Resolved Snyk-reported vulnerabilities (ENG-28465) | Resolved security vulnerabilities that Snyk reported in Core dependencies. |
| Core | Resolved event-system security vulnerabilities (ENG-28469) | Resolved security vulnerabilities in @itential/event-system. |
| Gateway | Updated adapter-utils and brace-expansion (ENG-28916) | Updated adapter-utils to 5.10.27 and the brace-expansion override to 2.1.6 to resolve vulnerabilities that Snyk reported. |
| itential-utils | Updated itential-utils security dependencies (ENG-28466) | Updated axios and fast-uri in itential-utils to resolve security vulnerabilities. |
| NSO Service Manager | Resolved a ReDoS vulnerability in ajv (ENG-27641) | Resolved a regular expression denial of service (ReDoS) vulnerability (CVE-2025-69873) by updating the ajv dependency. |
| NSO Service Manager | Resolved a prototype pollution vulnerability in app-nso_manager (ENG-27642) | Resolved a prototype pollution vulnerability (CVE-2026-42264) by updating axios in app-nso_manager. |
| NSO Service Manager | Resolved an improper input validation vulnerability in uuid (ENG-27650, ENG-28441) | Resolved an improper input validation vulnerability (CVE-2026-41907) by updating the uuid dependency. |
| NSO Service Manager | Resolved an infinite loop vulnerability in app-nso_manager (ENG-27651) | Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the uri-js dependency in app-nso_manager with a drop-in replacement. |
| NSO Service Manager | Resolved a ReDoS vulnerability in ajv and UI dependencies (ENG-27652) | Resolved a regular expression denial of service (ReDoS) vulnerability (CVE-2025-69873) by updating ajv and related UI dependencies. |
| NSO Service Manager | Resolved a prototype pollution vulnerability in axios (ENG-27653) | Resolved a prototype pollution vulnerability (CVE-2026-42264) by updating axios. |
| NSO Service Manager | Resolved an uncontrolled recursion vulnerability in commons-lang3 (ENG-27664) | Resolved an uncontrolled recursion vulnerability (CVE-2025-48924) by updating commons-lang3 to 3.18.0. |
| NSO Service Manager | Resolved a prototype pollution vulnerability in adapter-nso (ENG-27667) | Resolved a prototype pollution vulnerability (CVE-2023-0842) by updating xml2js in adapter-nso. |
| NSO Service Manager | Resolved an infinite loop vulnerability in app-service_management (ENG-28437) | Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the uri-js dependency in app-service_management with a drop-in replacement. |
| NSO Service Manager | Resolved an improper input validation vulnerability in adapter-nso (ENG-28446) | Resolved an improper input validation vulnerability (CVE-2026-41907) by updating uuid in adapter-nso. |
| NSO Service Manager | Resolved an improper input validation vulnerability in app-service_catalog (ENG-28457) | Resolved an improper input validation vulnerability (CVE-2026-41907) by updating uuid in app-service_catalog. |
| NSO Service Manager | Resolved an infinite loop vulnerability in adapter-nso (ENG-28514) | Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the uri-js dependency in adapter-nso with a drop-in replacement. |
| NSO Service Manager | Resolved an SSRF vulnerability in axios (ENG-29066, ENG-29089) | Resolved a server-side request forgery (SSRF) vulnerability (CVE-2026-101898) by updating axios to 1.20.0. |
| NSO Service Manager | Resolved an XSS vulnerability in DOMPurify (ENG-29228, ENG-29233) | Resolved a cross-site scripting (XSS) vulnerability by updating dompurify. |
| Operations Manager | Applied the 2023.2 security update (ENG-27101) | Applied the 2023.2 security update to Operations Manager. |
| Operations Manager | Resolved a vulnerability in postcss (ENG-27849) | Updated postcss to resolve a security vulnerability. |
| Operations Manager | Resolved a vulnerability in js-yaml (ENG-27850) | Updated js-yaml to resolve a security vulnerability. |
| Operations Manager | Resolved a vulnerability in browserslist (ENG-27851) | Updated browserslist to resolve a security vulnerability. |
| Operations Manager | Resolved a vulnerability in svgo (ENG-27852) | Updated svgo to resolve a security vulnerability. |
| Operations Manager | Resolved a vulnerability in ajv (ENG-27879) | Updated ajv to resolve a security vulnerability. |
| Operations Manager | Resolved a security vulnerability (ENG-27880) | Resolved a security vulnerability in Operations Manager. |
| Operations Manager | Resolved a vulnerability in lodash (ENG-27881) | Updated lodash to resolve a security vulnerability. |
| Operations Manager | Resolved a vulnerability in fast-uri (ENG-27884) | Updated fast-uri to resolve a security vulnerability. |
| Operations Manager | Resolved security vulnerabilities (ENG-27989, ENG-28197, ENG-28198, ENG-28199, ENG-28200, ENG-28201, ENG-28245) | Resolved security vulnerabilities in Operations Manager. |
| Operations Manager | Applied security updates (ENG-28009) | Applied security updates to Operations Manager. |
| Operations Manager | Updated dependencies to address security vulnerabilities (ENG-28195, ENG-28237, ENG-28253) | Updated third-party dependencies in Operations Manager to address security vulnerabilities. |
| Operations Manager | Updated rodeo-ui and component-workflow-canvas (ENG-28379) | Updated @itential/rodeo-ui and @itential/component-workflow-canvas to their latest versions to resolve several security vulnerabilities. |
| Operations Manager | Resolved a security vulnerability through an update (ENG-28504) | Applied an update to Operations Manager that resolves a security vulnerability. |
| Operations Manager | Applied dependency security patches (ENG-28507) | Applied security patches to Operations Manager dependencies. |
| Product adapters | Updated the nodemailer dependency (ENG-28463) | Updated nodemailer to resolve security vulnerabilities. |
| Workflow engine | Updated workflow engine security dependencies (ENG-28462) | Updated axios and moment, along with the transitive js-yaml and fast-uri dependencies, to resolve security vulnerabilities. |