Wiiisdom Cloud Platform - Third-party vulnerabilities (CVE) status

Wiiisdom Cloud Platform - Third-party vulnerabilities (CVE) status

Overview

This article lists the vulnerabilities (CVEs) reported on third-party libraries and components used by Wiiisdom Cloud Platform (including Wiiisdom for Power BI), whether the platform was affected, and the remediation. The list is sorted from the most recent CVE to the oldest.

Info
Wiiisdom Cloud Platform is a SaaS platform operated by Wiiisdom: security fixes are deployed by our team and no action is required on your side. Releases before 2026 used internal 1.x version numbers; the dates and public release names are given instead.

Legend

  • Not affected: the vulnerable code or feature is not used, not reachable or not configured in the product.
  • Low risk: the bundled component is in the affected range, but exploitation requires a non-default configuration or local access. It has been (or will be) upgraded anyway.
  • Affected – fixed: the product shipped an affected version of the component. The fixed product version is given in the details.
  • Not applicable: the component is not part of the product (for example, it belongs to a third-party platform installed on the same server).

Reported CVEs

CVEComponentImpactDetails & remediation
2026
CVE-2026-50559QuarkusAffected – fixedQuarkus upgraded to 3.33.2.1 in release 2026.7.0.
CVE-2026-33117Azure SDK for Java (Key Vault Keys 4.10.2)Affected – fixedCritical. Library upgraded to 4.10.6 in release 2026.6.1 (June 2026).
CVE-2026-4634
CVE-2026-4282
Third-party dependencyAffected – fixedFixed in security hotfix 2026.4.1 (April 2026).
CVE-2026-3009Keycloak (identity provider management)Affected – fixedKeycloak upgraded to 26.5.5 in security hotfix 2026.3.1.
CVE-2026-2603KeycloakAffected – fixedKeycloak upgraded in release 2026.4.0.
2025
Quarkus security advisoriesQuarkus / KeycloakAffected – fixedQuarkus upgraded to the 3.20 LTS line (2025.3), then to 3.20.2.1 with Keycloak 26.3.3 (2025.3.3, August 2025). The February 2025 Quarkus CVE fixes were applied in 2025.2 (April 2025).
2024
CVE-2024-39338axiosAffected – fixedaxios upgraded to 1.7.4 in August 2024 (2024.3).
CVE-2024-35255Azure Identity SDKLow riskMedium severity; exploitation requires access to the container. SDK updated in July 2024 (2024.3).
CVE-2024-8698Keycloak 25.0.x (SAML)Affected – fixedAffected the SAML login implementation. Keycloak upgraded to 25.0.6 in September 2024 (2024.3 hotfix, then 2024.4).
CVE-2024-7341Keycloak 25.0.1Affected – fixedKeycloak upgraded to 25.0.5 in September 2024 (2024.3 hotfix).
CVE-2024-2419
CVE-2024-1132
Keycloak < 24.0.3Low riskOur penetration tests could not exploit these vulnerabilities, with or without the Web Application Firewall. Keycloak upgraded to 24.0.3 in May 2024 (2024.2).
2022
CVE-2022-4147
CVE-2022-4116
Quarkus 2.xAffected – fixedQuarkus upgraded in January 2024 (2024.1).
CVE-2022-1471SnakeYAMLNot affectedYAML parsing is not used (Liquibase uses XML changelogs, Jackson YAML is only used at build time).

Other security events

  • November 2025 – Shai-Hulud 2.0 npm supply-chain attack: not affected. No compromised package was found in any Wiiisdom Cloud Platform component. Dependency installation has since been restricted to locked versions only.

Your CVE is not listed?

This page lists the vulnerabilities that were reported to us or analysed by our teams. It is not an exhaustive list of every CVE fixed by a component upgrade: check the Security section of the release notes for the complete list.

If your security scanner reports a CVE that is not listed here, open a ticket with the Support team and include the CVE ID, the product version, and the exact file or path flagged by the scanner. We will analyse it and add it to this page.