Skip to main content

Security Notes

Important

This release contains a critical issue that was resolved in C2025.6.2. If you are on C2025.5.0 or considering upgrading to it, you should instead upgrade to C2025.6.2. For more information, refer to the C2025.6.2 resolved issues.

The following security vulnerabilities have been addressed in this release.

Vulnerability Name/CVE-IDSeveritySubjectIssue TypeJIRA
GHSA-vjh7-7g9h-fjfhCRITICALSecurity UpdatePackageATSCALE-25044
CVE-2024-4068HIGHSecurity UpdatePackageATSCALE-25042
CVE-2025-27152HIGHSecurity UpdatePackageATSCALE-25820
CVE-2023-52428HIGHSecurity UpdatePackageATSCALE-25028
CVE-2024-10039HIGHSecurity UpdatePackageATSCALE-25027
CVE-2023-1370HIGHSecurity UpdatePackageATSCALE-25837
CVE-2024-21538HIGHSecurity UpdatePackageATSCALE-25720
CVE-2020-1938HIGHSecurity UpdatePackageATSCALE-27498
CVE-2025-24970HIGHSecurity UpdatePackageATSCALE-25041
CVE-2024-45590HIGHSecurity UpdatePackageATSCALE-23685
CVE-2021-29425HIGHSecurity UpdatePackageATSCALE-20680
Server-Side Request Forgery (SSRF)HIGHSecurity UpdatePentestATSCALE-24608