> This page is for Itential Platform On-Prem, version 2023.2.
> For other versions, use one of these documentation indexes:
> - 6 (default): https://docs.itential.com/itential-platform/6/llms.txt
> - 2023.2: https://docs.itential.com/itential-platform/2023-2/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.itential.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server.

# 2023.2.35

Platform 2023.2.35 is a maintenance release that addresses security vulnerabilities in third-party dependencies across Operations Manager, NSO Service Manager, Core, Configuration Manager Enterprise, Automation Catalog, and other Platform components.

#### Security fixes (43)

This release includes security updates that address vulnerabilities in third-party packages and Platform components.

| Component                        | Feature                                                                                                             | Description                                                                                                                                                                         |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Admin Essentials                 | **Updated Admin Essentials security dependencies** (ENG-28460)                                                      | Updated third-party dependencies in Admin Essentials, including `axios`, `swagger-ui-react`, `fast-uri`, `immutable`, `js-yaml`, and `moment`, to resolve security vulnerabilities. |
| Automation Catalog               | **Updated transitive dependencies** (ENG-27985)                                                                     | Updated transitive dependencies in Automation Catalog to resolve reported security vulnerabilities.                                                                                 |
| Automation Catalog               | **Updated a dependency to address a security vulnerability** (ENG-28295, ENG-28296)                                 | Updated a third-party dependency in Automation Catalog to address a security vulnerability.                                                                                         |
| Configuration Manager Enterprise | **Resolved Snyk-reported vulnerabilities** (ENG-26990, ENG-28147)                                                   | Resolved security vulnerabilities that Snyk reported in Configuration Manager Enterprise dependencies.                                                                              |
| Configuration Manager Enterprise | **Resolved a Snyk-reported vulnerability** (ENG-28774)                                                              | Resolved a security vulnerability that Snyk reported in a Configuration Manager Enterprise dependency.                                                                              |
| Core                             | **Updated Core security dependencies** (ENG-28459)                                                                  | Updated `axios`, `express`, `compression`, `moment`, `undici`, `brace-expansion`, `fast-uri`, and `js-yaml` to resolve security vulnerabilities.                                    |
| Core                             | **Upgraded packages to address a security vulnerability** (ENG-28461)                                               | Upgraded `moment`, `fast-uri`, `axios`, and `swagger-ui-react` to address a security vulnerability.                                                                                 |
| Core                             | **Updated the transitive fast-uri dependency** (ENG-28464)                                                          | Updated the transitive `fast-uri` dependency to resolve a security vulnerability.                                                                                                   |
| Core                             | **Resolved Snyk-reported vulnerabilities** (ENG-28465)                                                              | Resolved security vulnerabilities that Snyk reported in Core dependencies.                                                                                                          |
| Core                             | **Resolved event-system security vulnerabilities** (ENG-28469)                                                      | Resolved security vulnerabilities in `@itential/event-system`.                                                                                                                      |
| Gateway                          | **Updated adapter-utils and brace-expansion** (ENG-28916)                                                           | Updated `adapter-utils` to 5.10.27 and the `brace-expansion` override to 2.1.6 to resolve vulnerabilities that Snyk reported.                                                       |
| itential-utils                   | **Updated itential-utils security dependencies** (ENG-28466)                                                        | Updated `axios` and `fast-uri` in `itential-utils` to resolve security vulnerabilities.                                                                                             |
| NSO Service Manager              | **Resolved a ReDoS vulnerability in ajv** (ENG-27641)                                                               | Resolved a regular expression denial of service (ReDoS) vulnerability (CVE-2025-69873) by updating the `ajv` dependency.                                                            |
| NSO Service Manager              | **Resolved a prototype pollution vulnerability in app-nso\_manager** (ENG-27642)                                    | Resolved a prototype pollution vulnerability (CVE-2026-42264) by updating `axios` in `app-nso_manager`.                                                                             |
| NSO Service Manager              | **Resolved an improper input validation vulnerability in uuid** (ENG-27650, ENG-28441)                              | Resolved an improper input validation vulnerability (CVE-2026-41907) by updating the `uuid` dependency.                                                                             |
| NSO Service Manager              | **Resolved an infinite loop vulnerability in app-nso\_manager** (ENG-27651)                                         | Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the `uri-js` dependency in `app-nso_manager` with a drop-in replacement.                                      |
| NSO Service Manager              | **Resolved a ReDoS vulnerability in ajv and UI dependencies** (ENG-27652)                                           | Resolved a regular expression denial of service (ReDoS) vulnerability (CVE-2025-69873) by updating `ajv` and related UI dependencies.                                               |
| NSO Service Manager              | **Resolved a prototype pollution vulnerability in axios** (ENG-27653)                                               | Resolved a prototype pollution vulnerability (CVE-2026-42264) by updating `axios`.                                                                                                  |
| NSO Service Manager              | **Resolved an uncontrolled recursion vulnerability in commons-lang3** (ENG-27664)                                   | Resolved an uncontrolled recursion vulnerability (CVE-2025-48924) by updating `commons-lang3` to 3.18.0.                                                                            |
| NSO Service Manager              | **Resolved a prototype pollution vulnerability in adapter-nso** (ENG-27667)                                         | Resolved a prototype pollution vulnerability (CVE-2023-0842) by updating `xml2js` in `adapter-nso`.                                                                                 |
| NSO Service Manager              | **Resolved an infinite loop vulnerability in app-service\_management** (ENG-28437)                                  | Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the `uri-js` dependency in `app-service_management` with a drop-in replacement.                               |
| NSO Service Manager              | **Resolved an improper input validation vulnerability in adapter-nso** (ENG-28446)                                  | Resolved an improper input validation vulnerability (CVE-2026-41907) by updating `uuid` in `adapter-nso`.                                                                           |
| NSO Service Manager              | **Resolved an improper input validation vulnerability in app-service\_catalog** (ENG-28457)                         | Resolved an improper input validation vulnerability (CVE-2026-41907) by updating `uuid` in `app-service_catalog`.                                                                   |
| NSO Service Manager              | **Resolved an infinite loop vulnerability in adapter-nso** (ENG-28514)                                              | Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the `uri-js` dependency in `adapter-nso` with a drop-in replacement.                                          |
| NSO Service Manager              | **Resolved an SSRF vulnerability in axios** (ENG-29066, ENG-29089)                                                  | Resolved a server-side request forgery (SSRF) vulnerability (CVE-2026-101898) by updating `axios` to 1.20.0.                                                                        |
| NSO Service Manager              | **Resolved an XSS vulnerability in DOMPurify** (ENG-29228, ENG-29233)                                               | Resolved a cross-site scripting (XSS) vulnerability by updating `dompurify`.                                                                                                        |
| Operations Manager               | **Applied the 2023.2 security update** (ENG-27101)                                                                  | Applied the 2023.2 security update to Operations Manager.                                                                                                                           |
| Operations Manager               | **Resolved a vulnerability in postcss** (ENG-27849)                                                                 | Updated `postcss` to resolve a security vulnerability.                                                                                                                              |
| Operations Manager               | **Resolved a vulnerability in js-yaml** (ENG-27850)                                                                 | Updated `js-yaml` to resolve a security vulnerability.                                                                                                                              |
| Operations Manager               | **Resolved a vulnerability in browserslist** (ENG-27851)                                                            | Updated `browserslist` to resolve a security vulnerability.                                                                                                                         |
| Operations Manager               | **Resolved a vulnerability in svgo** (ENG-27852)                                                                    | Updated `svgo` to resolve a security vulnerability.                                                                                                                                 |
| Operations Manager               | **Resolved a vulnerability in ajv** (ENG-27879)                                                                     | Updated `ajv` to resolve a security vulnerability.                                                                                                                                  |
| Operations Manager               | **Resolved a security vulnerability** (ENG-27880)                                                                   | Resolved a security vulnerability in Operations Manager.                                                                                                                            |
| Operations Manager               | **Resolved a vulnerability in lodash** (ENG-27881)                                                                  | Updated `lodash` to resolve a security vulnerability.                                                                                                                               |
| Operations Manager               | **Resolved a vulnerability in fast-uri** (ENG-27884)                                                                | Updated `fast-uri` to resolve a security vulnerability.                                                                                                                             |
| Operations Manager               | **Resolved security vulnerabilities** (ENG-27989, ENG-28197, ENG-28198, ENG-28199, ENG-28200, ENG-28201, ENG-28245) | Resolved security vulnerabilities in Operations Manager.                                                                                                                            |
| Operations Manager               | **Applied security updates** (ENG-28009)                                                                            | Applied security updates to Operations Manager.                                                                                                                                     |
| Operations Manager               | **Updated dependencies to address security vulnerabilities** (ENG-28195, ENG-28237, ENG-28253)                      | Updated third-party dependencies in Operations Manager to address security vulnerabilities.                                                                                         |
| Operations Manager               | **Updated rodeo-ui and component-workflow-canvas** (ENG-28379)                                                      | Updated `@itential/rodeo-ui` and `@itential/component-workflow-canvas` to their latest versions to resolve several security vulnerabilities.                                        |
| Operations Manager               | **Resolved a security vulnerability through an update** (ENG-28504)                                                 | Applied an update to Operations Manager that resolves a security vulnerability.                                                                                                     |
| Operations Manager               | **Applied dependency security patches** (ENG-28507)                                                                 | Applied security patches to Operations Manager dependencies.                                                                                                                        |
| Product adapters                 | **Updated the nodemailer dependency** (ENG-28463)                                                                   | Updated `nodemailer` to resolve security vulnerabilities.                                                                                                                           |
| Workflow engine                  | **Updated workflow engine security dependencies** (ENG-28462)                                                       | Updated `axios` and `moment`, along with the transitive `js-yaml` and `fast-uri` dependencies, to resolve security vulnerabilities.                                                 |