diff --git a/backend/Dockerfile b/backend/Dockerfile index eb2cb45..6c00f63 100644 --- a/backend/Dockerfile +++ b/backend/Dockerfile @@ -1,6 +1,6 @@ # eclipse-temurin:21-jre-alpine FROM eclipse-temurin:25-jre-alpine@sha256:28db6fdf60e38945e43d840c0333aeaec66c15943070104f7586fd3c9d1665b0 -RUN apk upgrade --no-cache p11-kit p11-kit-trust libexpat +RUN apk upgrade --no-cache p11-kit p11-kit-trust libexpat openssl libssl3 RUN addgroup -S appgroup && adduser -S appuser -G appgroup WORKDIR /app COPY build/libs/*.jar app.jar diff --git a/backend/build.gradle.kts b/backend/build.gradle.kts index ddcf102..135501a 100644 --- a/backend/build.gradle.kts +++ b/backend/build.gradle.kts @@ -74,6 +74,15 @@ extra["logback.version"] = "1.5.35" // postgresql 42.7.11 -> 42.7.12 fixes CVE-2026-54291 (HIGH). Spring Boot 3.5.16 BOM pins 42.7.11; // override the managed property so the runtime JDBC driver picks up the patched release. extra["postgresql.version"] = "42.7.12" +// tomcat-embed 10.1.55 -> 10.1.59 fixes three CRITICAL auth-bypass CVEs (disclosed 2026-09-03, +// caught by the nightly Trivy scan): CVE-2026-68525 (FORM authentication bypass), CVE-2026-65905 +// (DIGEST authenticator replay) and CVE-2026-65182 (security constraint bypass). +// The advisories name 10.1.58 as the fix, but that release was never published to Maven Central +// (404) — 10.1.59 is the first available release carrying the fixes. Spring Boot 3.5.16 is the +// latest 3.5.x and still pins 10.1.55, and tomcat-embed-core is transitive-only here, so +// Dependabot's direct-only security update could not patch it (security_update_dependency_not_found). +// Override the shared property so core, el and websocket move together. +extra["tomcat.version"] = "10.1.59" // Override Spring Boot BOM version for Testcontainers to support Docker Desktop 4.x on Windows dependencyManagement { diff --git a/backend/gradle.lockfile b/backend/gradle.lockfile index 92ea768..a1bee43 100644 --- a/backend/gradle.lockfile +++ b/backend/gradle.lockfile @@ -73,9 +73,9 @@ org.apache.commons:commons-compress:1.28.0=testCompileClasspath,testRuntimeClass org.apache.commons:commons-lang3:3.18.0=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath org.apache.logging.log4j:log4j-api:2.24.3=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath org.apache.logging.log4j:log4j-to-slf4j:2.24.3=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath -org.apache.tomcat.embed:tomcat-embed-core:10.1.55=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath -org.apache.tomcat.embed:tomcat-embed-el:10.1.55=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath -org.apache.tomcat.embed:tomcat-embed-websocket:10.1.55=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath +org.apache.tomcat.embed:tomcat-embed-core:10.1.59=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath +org.apache.tomcat.embed:tomcat-embed-el:10.1.59=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath +org.apache.tomcat.embed:tomcat-embed-websocket:10.1.59=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath org.apiguardian:apiguardian-api:1.1.2=testCompileClasspath org.aspectj:aspectjweaver:1.9.25.1=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath org.assertj:assertj-core:3.27.7=testCompileClasspath,testRuntimeClasspath diff --git a/frontend/Dockerfile b/frontend/Dockerfile index 0edb156..23506e7 100644 --- a/frontend/Dockerfile +++ b/frontend/Dockerfile @@ -10,7 +10,9 @@ RUN npm run build FROM nginx:alpine@sha256:4a73073bd557c65b759505da037898b61f1be6cbcc3c2c3aeac22d2a470c1752 # libexpat 2.8.1-r0 -> 2.8.2-r0 (CVE-2026-56131/56407/56408); c-ares 1.34.6-r0 -> 1.34.8-r0 (CVE-2026-33630) # curl/libcurl 8.19.0-r0 -> 8.20.0-r0 (CVE-2026-5773/6276) -RUN apk upgrade --no-cache libexpat c-ares curl +# libssl3/libcrypto3 3.5.7-r0 -> 3.5.8-r0 (CVE-2026-14456, same openssl flaw patched in backend/Dockerfile) +# libuuid 2.42.1-r0 -> 2.42.3-r1 (CVE-2026-78408/78409/78410, -76642, -53612/53613/53614) +RUN apk upgrade --no-cache libexpat c-ares curl libssl3 libcrypto3 libuuid COPY --from=builder /app/dist /usr/share/nginx/html COPY nginx-spa.conf /etc/nginx/conf.d/default.conf EXPOSE 80 diff --git a/frontend/package-lock.json b/frontend/package-lock.json index b512ee7..082d0ea 100644 --- a/frontend/package-lock.json +++ b/frontend/package-lock.json @@ -1,12 +1,12 @@ { "name": "taskowolf-frontend", - "version": "1.0.13", + "version": "1.0.15", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "taskowolf-frontend", - "version": "1.0.13", + "version": "1.0.15", "dependencies": { "@dnd-kit/core": "^6.1.0", "@dnd-kit/sortable": "^10.0.0", @@ -3201,9 +3201,9 @@ "license": "MIT" }, "node_modules/nanoid": { - "version": "3.3.16", - "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.16.tgz", - "integrity": "sha512-bzlKTyNJ7+LdGIIwy8ijFpIqEQIvafahV7eYykJ8Cvh42EdJeODoJ6gUJXpQJvej1BddH8OqTXZNE/KfbWAu8Q==", + "version": "3.3.18", + "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.18.tgz", + "integrity": "sha512-DTg4MJbGMWkfi6VZFdNt2/caMbQy4Ou+Op/hJQvGEWcnVfoA1QA+xzRKAzw9jD6+GVOOeYr/mIcuDSdug6F6+w==", "dev": true, "funding": [ {